awesome-yara
by InQuest
A curated list of awesome YARA rules, tools, and people.
AI summary
YARA library
A curated collection of YARA rules and tools for malware analysis and threat detection.
- stars
- 3.6K
- forks
- 495
- watching
- 175
- awesome lists
- 9
- entries
- 259
What's in the list
259 links in 42 sections, with live GitHub stats.activeno commit in 2y
Guides
Rules
Rules / AlienVault Labs Rules
- AlienVault Labs
Collection of tools, signatures, and rules from the researchers at . Search the repo for .yar and .yara extensions to find about two dozen rules ranging from APT detection to generic sandbox / VM detection. Last updated in January of 2016
Rules
Rules / CDI Rules
- CyberDefenses
Collection of YARA rules released by for public use. Built from information in intelligence profiles, dossiers and file work
Rules
Rules / Deadbits Rules
- Adam Swanda
A collection of YARA rules made public by , Splunk's Principal Threat Intel. Analyst, from his own recent malware research
Rules
Rules / Didier Stevens Rules
- NVISO Labs Blog
Collection of rules from Didier Stevens, author of a suite of tools for inspecting OLE/RTF/PDF. Didier's rules are worth scrutinizing and are generally written purposed towards hunting. New rules are frequently announced through the
Rules
Rules / ESET IOCs
- ESET WeLiveSecurity Blog
Collection of YARA and Snort rules from IOCs collected by ESET researchers. There's about a dozen YARA Rules to glean from in this repo, search for file extension .yar. This repository is seemingly updated on a roughly monthly interval. New IOCs are often mentioned on the
Rules
Rules / f0wl yara_rules
- https://dissectingmalwa.re/
A collection of Yara rules from blog posts
Rules
Rules / Frank Boldewin's Rules
- @r3c0nst
A collection of YARA Rules from
Rules
Rules / InQuest Rules
- InQuest Blog
YARA rules published by InQuest researchers mostly geared towards threat hunting on Virus Total. Rules are updated as new samples are collected and novel pivots are discovered. The will often discuss new findings
Rules
Rules / Yara-Unprotect
Tools
Tools / a-ray-grass
- hashlookup.io
YARA module that provides support for bloom filters in yara. In the context of , it allows to quickly discard known files before any further analysis
Tools
Tools / CSE-CST AssemblyLine
- AssemblyLine
The Canadian Communications Security Establishment (CSE) open sourced , a platform for analyzing malicious files. The component linked here provides an interface to YARA
Tools
Tools / Fibratus
- support for YARA
A modern tool for Windows kernel exploration and observability with a focus on security and
Tools
GhidraYara
A Ghidra extension providing direct integration of YARA through an analyzer, as well as rule generation from code listings and management in the Ghidra UI. Supports an extensive library of cryptographic constants, CRC tables, etc
Tools / Laika BOSS
Tools
Tools / Nextron Systems OSS and Commercial Tools (Florian Roth: @Neo23x0)
Tools
Tools / VTCodeSimilarity-YaraGen
- @arieljt
Yara rule generator using VirusTotal code similarity feature written by
Tools
YaraGen
and
Tools / yara-java
old bindings
Java bindings for YARA (Subreption fork, maintained as of 2024, )
Tools
Yaramanager
( )
Tools / YARA-sort
- blog
Aggregate files into collections basd on YARA rules
Tools
Tools / yaraScanParser
- Yara Scan Service
Parsing tool for 's JSON output file
Tools
Services
Syntax Highlighters
language-yara
Atom:
yara-mode
Emacs:
GtkSourceView-YARA
GTK-based editors, like gedit and xed:
userDefinedLanguages
Notepad++:
YaraSyntax
Sublime Text:
vim-yara
Vim: ,
vscode-yara
Visual Studio Code:
Videos and Talks
Related Awesome Lists
Nothing in this list matches your filter.
Featured in 9 awesome lists
Each link jumps to the spot where the list mentions awesome-yara.