30 open-source projects similar to target/halogen, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Halogen alternative.
Yet Another Yara Automaton - Automatically curate open source yara rules and run scans
A tool to help malware analysts signature unique parts of RTF documents
MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish
YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA
This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as
A Yara rule generator for finding related samples and hunting
AI-assisted malware reverse-engineering debugger with ATT&CK, YARA, IOC, JSON, and analyst report output
Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets
A multi-platform .Net wrapper library for the native Yara library.
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Clojure YARA-style pattern matching - malware signatures, hex/ascii/regex patterns
Performs OCR on image files and scans them for matches to YARA rules
Repository that contains a set of purposefully erroneous Yara rules.
Yara integrated software to handle archive file data.
Python 3 tool to parse Yara rules (extension of yarabuilder)
A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.