awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

YARA Malware Detection Rules

Ranking updated Jun 30, 2026

For a malware detection rule toolkit, the first results are cystack/stealer-fingerprints (This repository delivers exactly what you need: a public catalog of YARA rules for 30+ stealer malware families RedLine, Vidar, Lumma, etc., built for incident response and detection engineering, with community-contributed fingerprints and field signatures), neo23x0/signature-base (neo23x0/signature-base is a repository of YARA signatures and IOCs, giving you pre-written rules for malware detection and integration with threat intelligence feeds, which directly matches the search for a YARA rule repository) and elastic/protections-artifacts. eset/malware-ioc and yara-rules/rules round out the shortlist. Compare the match explanations and check the project documentation against your requirements.

Collection of open-source YARA rule sets designed to identify and analyze specific malware family signatures.

YARA Malware Detection Rules

Find the best repos with AI.We'll search the best matching repositories with AI.
  • cystack/stealer-fingerprintscystack avatar

    cystack/stealer-fingerprints

    2View on GitHub↗

    Public catalog of stealer log fingerprints. Banner strings, field signatures, sanitized samples, and YARA rules for 30+ malware families including RedLine, Vidar, Lumma, StealC, and Rhadamanthys. For incident response, detection engineering, and threat intelligence research.

    This repository delivers exactly what you need: a public catalog of YARA rules for 30+ stealer malware families (RedLine, Vidar, Lumma, etc.), built for incident response and detection engineering, with community-contributed fingerprints and field signatures.

    YARAYara Rule Collections
    View on GitHub↗2
  • neo23x0/signature-baseNeo23x0 avatar

    Neo23x0/signature-base

    2,975View on GitHub↗

    YARA signature and IOC database for my scanners and tools

    neo23x0/signature-base is a repository of YARA signatures and IOCs, giving you pre-written rules for malware detection and integration with threat intelligence feeds, which directly matches the search for a YARA rule repository.

    YARAYara Rule CollectionsThreat Intelligence Feeds
    View on GitHub↗2,975
  • elastic/protections-artifactselastic avatar

    elastic/protections-artifacts

    1,441View on GitHub↗

    Elastic Security detection content for Endpoint

    Elastic's protections-artifacts repository provides a comprehensive, pre-written set of YARA rules for endpoint malware detection, backed by Elastic's security research and community contributions, which exactly matches your need for a YARA rule collection with community involvement.

    YARAYara Rule Collections
    View on GitHub↗1,441
  • eset/malware-ioceset avatar

    eset/malware-ioc

    1,955View on GitHub↗

    Indicators of Compromises (IOC) of our various investigations

    ESET's malware-ioc repository provides YARA rules and indicators of compromise from their investigations, making it a relevant source of pre-written malware family rules for YARA-based detection.

    YARAYara Rule CollectionsThreat Intelligence Feeds
    View on GitHub↗1,955
  • yara-rules/rulesYara-Rules avatar

    Yara-Rules/rules

    4,712View on GitHub↗

    This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r

    This repository is a community-curated collection of YARA rules for detecting malware, webshells, and other malicious patterns, which directly matches the request for pre-written rules with community contributions and threat intelligence integration.

    YARAMalware Family IdentificationYara Rule CollectionsThreat Intelligence Feeds
    View on GitHub↗4,712
  • anyrun/yaraanyrun avatar

    anyrun/YARA

    29View on GitHub↗

    Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.

    anyrun/yara is a community-maintained collection of YARA rules targeting malware families from the ANY.RUN team, directly matching the request for pre-written detection rules, though it does not explicitly include rule testing tools or malware feed integration.

    YARAYara Rule Collections
    View on GitHub↗29
  • bartblaze/yara-rulesbartblaze avatar

    bartblaze/Yara-rules

    385View on GitHub↗

    Collection of private Yara rules.

    This repository is a private collection of YARA rules for malware detection, fitting the request for a rule repository, but as a single-author collection it may be less comprehensive than larger community-driven rule sets and lacks built-in testing or feed integration.

    YARAYara Rule Collections
    View on GitHub↗385
  • chronicle/gctichronicle avatar

    chronicle/GCTI

    553View on GitHub↗

    This repository contains GCTI's open source detection signatures.

    GCTI’s repository provides ready-made YARA detection signatures for malware families from Google Cloud Threat Intelligence, which directly fits the need for a community-oriented YARA rule repository, though it lacks built-in testing or feed integration.

    YARAYara Rule Collections
    View on GitHub↗553
  • deadbits/yara-rulesdeadbits avatar

    deadbits/yara-rules

    44View on GitHub↗

    Collection of YARA signatures from individual research

    deadbits/yara-rules is a repository of YARA signatures from individual research, providing pre-written malware detection rules that directly match your need for YARA rulesets, though it lacks built-in testing/validation or feed integration features.

    YARAYara Rule Collections
    View on GitHub↗44
  • delivr-to/detectionsdelivr-to avatar

    delivr-to/detections

    75View on GitHub↗

    A home for detection content developed by the delivr.to team

    A YARA rule collection from the delivr.to team, matching the request for a repository of detection rules, though it lacks explicit rule testing/validation or malware feed integration features.

    YARAYara Rule Collections
    View on GitHub↗75
  • ditekshen/detectionditekshen avatar

    ditekshen/detection

    254View on GitHub↗

    Detection in the form of Yara, Snort and ClamAV signatures.

    This repository contains YARA signatures alongside Snort and ClamAV rules, making it a valid YARA rule repository for malware detection, though it does not explicitly provide rule testing or feed integration.

    YARAYara Rule Collections
    View on GitHub↗254
  • fboldewin/yara-rulesfboldewin avatar

    fboldewin/YARA-rules

    70View on GitHub↗

    Some YARA rules i will add from time to time

    This is a personal collection of YARA rules from a single author, which fits as a repository of malware detection rules but lacks community contributions, testing tools, or integration with threat feeds.

    YARAYara Rule Collections
    View on GitHub↗70
  • fideliscyber/indicatorsF

    fideliscyber/indicators

    0View on GitHub↗

    This repository is tagged as a YARA rule collection, making it directly relevant for finding pre-written malware detection rules, though the empty description means its exact scope and features are unconfirmed.

    Yara Rule Collections
    View on GitHub↗0
  • filescanio/fsyarafilescanio avatar

    filescanio/fsYara

    22View on GitHub↗

    A collection of curated YARA rules used as part of the Filescan.io service

    A curated collection of YARA rules from the Filescan.io service, giving you pre-written detection rules for malware families, though it is a service-specific set rather than a broad community repository.

    YARAYara Rule Collections
    View on GitHub↗22
  • advanced-threat-research/yara-rulesadvanced-threat-research avatar

    advanced-threat-research/Yara-Rules

    626View on GitHub↗

    Repository of YARA rules made by Trellix ATR Team

    This is a dedicated collection of YARA rules from the Trellix ATR team, directly targeting malware detection with pre-written rules, fitting the search for a YARA rule repository for detecting specific malware families.

    YARAYara Rule Collections
    View on GitHub↗626
  • citizenlab/malware-signaturescitizenlab avatar

    citizenlab/malware-signatures

    143View on GitHub↗

    Yara rules for malware families seen as part of targeted threats project

    This repository contains YARA rules written for malware families tracked by the Citizen Lab's targeted threats project, giving you pre-written detection signatures that directly match the request for malware-specific rulesets.

    VimLYara Rule Collections
    View on GitHub↗143
  • codewatchorg/burp-yara-rulescodewatchorg avatar

    codewatchorg/Burp-Yara-Rules

    49View on GitHub↗

    Yara rules to be used with the Burp Yara-Scanner extension

    This repository is a collection of YARA rules designed for the Burp Yara-Scanner extension, so it fits the YARA rule repository category, but the rules are focused on passive web scanning rather than the broad malware-family detection you are seeking.

    YARAYara Rule Collections
    View on GitHub↗49
  • kevthehermit/yararuleskevthehermit avatar

    kevthehermit/YaraRules

    52View on GitHub↗

    My Yara Rules Collection

    This repository is a collection of YARA rules for malware detection, matching your need for pre-written rules even though it does not include built-in testing tools or feed integration.

    Yara Rule Collections
    View on GitHub↗52
  • neo23x0/yargenNeo23x0 avatar

    Neo23x0/yarGen

    1,796View on GitHub↗

    yarGen is a generator for YARA rules

    yarGen is a generator for creating YARA rules from strings in malicious files, making it a helpful tool for rule creation but not a repository of pre-written malware family rules.

    PythonYara Rules
    View on GitHub↗1,796
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
cystack/stealer-fingerprints2YARAApache-2.0Jun 9, 2026
neo23x0/signature-base3KYARANOASSERTIONJun 15, 2026
elastic/protections-artifacts
1.4K
YARA
NOASSERTION
Jun 8, 2026
eset/malware-ioc2KYARABSD-2-ClauseJun 16, 2026
yara-rules/rules4.7KYARAgpl-2.0Apr 16, 2024
anyrun/yara29YARA—Nov 1, 2025
bartblaze/yara-rules385YARAMITJan 28, 2026
chronicle/gcti553YARAApache-2.0Dec 4, 2023
deadbits/yara-rules44YARAUnlicenseNov 20, 2023
delivr-to/detections75YARA—Aug 10, 2025

Related searches

  • a detection-as-code ruleset
  • Malware Analysis and Reverse Engineering
  • a binary unpacking toolkit
  • Malware protection tool
  • a forensic triage tool
  • an open source file and url scanner
  • an open source antivirus for system protection
  • an open source malware scanner and remover