Issues
- 0
Help
#328 opened by tmorganPDC - 6
- 0
- 3
False Positive in Rule WEBSHELL_PHP_Dynamic_Big
#317 opened by gotmls - 0
False positive Trojan:Script/Phonzy.A!ml
#319 opened by groupecraft - 2
False positive for the WEBSHELL_PHP_Dynamic_Big rule
#309 opened by vsushkov - 1
Invalid MD5 entry
#305 opened by SkewedZeppelin - 1
gen_mal_3cx_compromise_mar23.yar
#303 opened by DYarizadeh - 5
- 1
- 1
False Positive?
#282 opened by derpeste - 1
Generic JSP Webshell false negative
#271 opened by orapic - 0
- 0
Yar file detected as suspicious file in Window
#262 opened by knowpage - 1
VT thor comments break on semicolon
#237 opened by ruppde - 2
How to run this
#246 opened by HackersBun - 3
expl_outlook_cve_2023_23397.yar syntax error
#249 opened by celevra - 0
False positive with Wordpress_Config_Webshell_Preprend rule in thor-webshells.yar
#228 opened by CyberCr33p - 1
false positive domains in "US-CERT TA17-293A"
#226 opened by marcuskbr - 2
Wrong file ending?
#225 opened by zagge-cgeo - 5
Backdoor:PHP/Dirtelti:HA in thor-webshells.yar ?
#217 opened by bekuno - 2
Reporting false positive: Synology Drive Client
#214 opened by NikGnuel - 1
ascore instead of score in f5 rule
#198 opened by petiepooo - 1
- 2
- 1
False Positive from Vim package
#210 opened by Fryyyyy - 2
- 2
- 1
SUSP_Reversed_Base64_Encoded_EXE
#148 opened by y0d4a - 1
thor lite folder and url shortcut
#150 opened by JayDee168 - 1
ProxyShell webshell YARA rules - compiling error
#156 opened by santhuj93 - 1
Tetris YARA Rule - Includes simple rule
#172 opened by SasquatchSecurity - 0
Non-Acunetix file FP for rule CN_Honker_Acunetix_Web_Vulnerability_Scanner_8_x_Enterprise_Edition_KeyGen
#177 opened by caliskanfurkan - 0
False Positive: foo.txt file
#182 opened by annagustav - 0
- 1
False Positives: APT_DarkHydrus_Jul18_4
#195 opened by ForensicITGuy - 3
False positive legitimate kernel32.dll and pcasvc.dll
#187 opened by st3l1n - 1
False Positives for some Norton 360 files
#181 opened by GerardVIE - 0
False Positive - aviatnetworks.com
#169 opened by upcboy - 0
Switch to Detection Rule License (DRL 1.0)
#147 opened by Neo23x0 - 1
false positive
#115 opened by MandiYang - 1
- 1
- 2
False Positive for plugin Thrive WordPress
#144 opened by rafaelarcanjo - 0
- 1
Wrong CVE for Hafnium?
#133 opened by trtracer - 1
crime_dearcry_ransom.yar string s5 is there twice
#129 opened by LeanVel - 2
No update
#124 opened by EstherMoellman - 0
Logging detection
#127 opened by acoral2 - 0
False Positive: sosreport files
#96 opened by steezermcfresh