YARA-PE-Features

Executable analysis presentation

A presentation project showcasing how to quickly analyze executable files using YARA and PE features

Slides from Cyber Defense Summit 2021

GitHub

4 stars
2 watching
1 forks
last commit: almost 5 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
virustotal/yara-pythonA Python interface to use YARA's features from Python programs665
rpgeeganage/audit-node-modules-with-yaraA tool to scan node modules for malicious scripts by applying YARA rules20
yara-rules/yara-endpointA tool used to scan files and assets for malware using Yara signatures, offering incident response capabilities.104
justicerage/manalyzeAnalyzes PE files for security vulnerabilities and suspicious behavior1,024
chronicle/gctiThis repository contains signature files for detecting malicious software533
exp-sky/xkungfoo-2013Analyzing and exploiting IE 0day vulnerabilities to demonstrate rapid, deep, and accurate analysis methods6
spyre-project/spyreA modular host-based IOC scanner built around YARA pattern matching engine164
dragon-dreamer/binary-valentineAn executable file analyzer tool that detects security, configuration, optimization, system, and format issues in Windows executables18
microsoft/libyara.netA .NET wrapper for the yara threat intelligence analysis library, providing a simplified API for integrating yara into .NET projects.52
yazgoo/bemaA Rust-based slideshow tool with multiple display options and interactive features.22
diablohorn/yara4pentestersA tool to identify files containing sensitive information using YARA rules125
k-atc/peidAn implementation of a PEiD-like tool with Yara rule analysis capabilities17
virustotal/yaraTool to create and match patterns for identifying malware samples8,370
lprat/static_file_analysisAnalyzes files to detect malware and extract embedded content49
dissectmalware/yaradbg-backendAn application backend designed to facilitate Yara rule analysis and root cause identification in malware detection.24