Pinned Repositories
100daysofYARA2024
Rules shared by the community from 100 Days of YARA 2024
Absolutely-Positively-NOT-Hacking-Back-with-Pcap
Streaming Unexpected Network Byte Sequences with High Probability of Blue Screening or Otherwise Crashing Attacker Command-and-Control Nodes
Cerebro
Scripts and lists to help generate YARA friendly string mutations
ConventionEngine
ConventionEngine - A Yara Rulepack for PDB Path Hunting
Reversing-the-Reversing-of-the-TriStation-Protocol
"Reversing the Reversing of the TriStation Protocol" presented at SEC-T 0x0B in 2018
RonnieColemanYARAParser
An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.
threat-research
Repository of tools, YARA rules, and code-snippets from Stairwell's research team.
TriStation-Wireshark-Dissector
Basic Wireshark LUA dissector for TriStation Protocol
stvemillertime's Repositories
stvemillertime/AlphaGolang
IDApython Scripts for Analyzing Golang Binaries
stvemillertime/Reversing-the-Reversing-of-the-TriStation-Protocol
"Reversing the Reversing of the TriStation Protocol" presented at SEC-T 0x0B in 2018
stvemillertime/ScareCrow
ScareCrow - Payload creation framework designed around EDR bypass.
stvemillertime/yarabuilder
Python 3 library to build YARA rules.
stvemillertime/ail-yara-rules
A set of YARA rules for the AIL framework to detect leak or information disclosure
stvemillertime/awesome-yara
A curated list of awesome YARA rules, tools, and people.
stvemillertime/beercode
Free beerware-quality code in exchange for beer money (if you are so inclined). ;-)
stvemillertime/binlex
A Binary Genetic Traits Lexer
stvemillertime/cosmopolitan
build-once run-anywhere c library
stvemillertime/Custom-Rules-ClamAV
Berikut merupakan custom rules YARA untuk ClamAV
stvemillertime/DALHelper
Just handle MSSQL, Access, Oracle in one DLL. Support simple, quick query and mapper via DALHelper
stvemillertime/klara
Kaspersky's GReAT KLara
stvemillertime/Manalyze
A static analyzer for PE executables.
stvemillertime/mcbyara
stvemillertime/mkYARA
Generating YARA rules based on binary code
stvemillertime/Python-Custom-Base64-decoder
stvemillertime/Redline_2021_stealer
stvemillertime/SampleRestAPI
Sample Restfull API using asp.net Webapi and using JWT to authentication and authorization.
stvemillertime/ShellCodeLoaderDlang
A class to load shellcode in memory written in D
stvemillertime/siglearn
Code for BH21 talk: "Generating YARA Rules by Classifying Malicious Byte Sequences"
stvemillertime/SigThief
Stealing Signatures and Making One Invalid Signature at a Time
stvemillertime/SimSocks5
Socks5 to your system.
stvemillertime/sunburst_countermeasures
stvemillertime/threatminutiae
Threat Minutiae
stvemillertime/time_decode
A timestamp and date decoder written for python 3
stvemillertime/unxor
unXOR will search a XORed file and try to guess the key using known-plaintext attacks.
stvemillertime/yara-goodies
Useful scripts, rules etc. for use with YARA
stvemillertime/yarabuilder-examples
Example scripts to show applications of the Python package "yarabuilder"
stvemillertime/yarix
stvemillertime/yaya
Yet Another Yara Automaton - Automatically curate open source yara rules and run scans