Information

Not all these have been fully tested so keep that in mind. They work for my purposes, and they should also work for yours.

I'll add more info when I get some time...

EXE

These are rules for detecting some malicious EXEs

RTF

These are rules for detecting some malicious RTFs

WEB

There are rules to run against weblogs (possible FPs) as well as some for detecting webshells. The HTML, GIF, and PHP one work really well.

PCAPs

For now this is just to search Virus Total for uploaded PCAPs for intel gathering.

Special Thanks

Special thanks to Virus Total for setting me up with a researcher account so I can test these Yara rules before I pass them off to the public for consumption. Much appreciated.