stvemillertime's Stars
getreu/stringsext
Find multi-byte-encoded strings in binary data (Gitlab mirror).
stvemillertime/Cerebro
Scripts and lists to help generate YARA friendly string mutations
0xTriboulet/Revenant
Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework
ald3ns/copy-as-yara
This is a little plugin to copy disassembly in a way that is usable in YARA rules!
mrphrazer/obfuscation_detection
Binary Ninja plugin to identify obfuscated code and other interesting code constructs
xorhex/mlget
A golang CLI tool to download malware from a variety of sources.
Neo23x0/YARA-Performance-Guidelines
A guide on how to write fast and memory friendly YARA rules
stvemillertime/100DaysofYARA-2023
Rules Shared by the Community from 100 Days of YARA 2023
colincowie/100DaysOfYara_2023
#100DaysOfYara is a challenge in which participants aim to create 100 Yara rules over the course of 100 days. This could involve creating new rules to identify previously unknown malware, or updating and improving existing rules.
sophos/yaraml_rules
Security ML models encoded as Yara rules
StrangerealIntel/CyberThreatIntel
Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups
lsoumille/Yara_Merger
Merge all Yara rules from official Yara github repository in one .yar file
hillu/go-yara
Go bindings for YARA
stvemillertime/hashdb
Assortment of hashing algorithms used in malware
aaronst/nodes
A collection of Synapse node files.
LiveMirror/pcshare
plyara/plyara
Parse YARA rules and operate over them more easily.
vivisect/vivisect
FuzzySecurity/WWHF-WayWest-2022
trustedsec/ELFLoader
MortenSchenk/Token-Stealing-Shellcode
trendmicro/tlsh
ace-ecosystem/yara_scanner
A Python wrapper library for libyara and a local server for fully utilizing the CPUs of the system to scan with yara...with additional capabilities.
mbrengel/yarix
tombonner/tbostrings
Dump printable ASCII/UNICODE strings from a given file in a single pass.
taviso/loadlibrary
Porting Windows Dynamic Link Libraries to Linux
boku7/azureOutlookC2
Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North Korean APT InkySquid / ScarCruft / APT37. TTP: Use Microsoft Graph API for C2 Operations.
enkomio/RunDotNetDll
A simple utility to list all methods of a given .NET Assembly and to invoke them
pwntester/ysoserial.net
Deserialization payload generator for a variety of .NET formatters
KasperskyLab/klara
Kaspersky's GReAT KLara