30 open-source projects similar to neo23x0/yargen, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best YarGen alternative.
A Yara rule generator for finding related samples and hunting
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
Defanged Indicator of Compromise (IOC) Extractor.
Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq
AI-assisted malware reverse-engineering debugger with ATT&CK, YARA, IOC, JSON, and analyst report output
Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.
Clojure YARA-style pattern matching - malware signatures, hex/ascii/regex patterns
Performs OCR on image files and scans them for matches to YARA rules
Repository that contains a set of purposefully erroneous Yara rules.
Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets
A multi-platform .Net wrapper library for the native Yara library.
Contributed by Check Point Software Technologies LTD. Programmed by Yaraslau Harakhavik
Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.
Validates yara rules and tries to repair the broken ones.
Automated static analysis tools for binary programs
Origami is a Ruby framework designed to parse, analyze, and forge PDF documents.
CrowdStrike Feed Management System. CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the Private API system. This framework automatically downloads recent samples, which triggered an alert on the users YARA notification feed.
YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA