1 dépôt
The process of assigning malware samples to known families based on identified patterns.
Distinct from Malware Detection Rules: Focuses on the classification result (family identification) rather than just the rules used for detection.
Explore 1 awesome GitHub repository matching part of an awesome list · Sample Classification. Refine with filters or upvote what's useful.
YARA is a pattern matching engine and binary analysis tool used to identify and classify malware samples. It functions as a malware research framework that allows for the definition of file descriptions and detection rules to find indicators of compromise within binaries. The system enables the creation of custom detection rules using strings, wildcards, and regular expressions. These rules use boolean logic to match textual or binary patterns, allowing for the classification of files into specific malware families and the automation of threat intelligence. The engine utilizes Aho-Corasick s
Identifies known malware families by matching files against specific textual and binary patterns.