awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to yara-rules/rules

Open-source alternatives to Rules

30 open-source projects similar to yara-rules/rules, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Rules alternative.

  • eset/malware-ioceset avatar

    eset/malware-ioc

    1,955View on GitHub↗

    Indicators of Compromises (IOC) of our various investigations

    YARA
    View on GitHub↗1,955
  • fireeye/iocsfireeye avatar

    fireeye/iocs

    470View on GitHub↗

    FireEye Publicly Shared Indicators of Compromise (IOCs)

    View on GitHub↗470
  • aptnotes/dataaptnotes avatar

    aptnotes/data

    1,794View on GitHub↗

    APTnotes data

    View on GitHub↗1,794
  • virustotal/yaraVirusTotal avatar

    VirusTotal/yara

    9,420View on GitHub↗

    YARA is a pattern matching engine and binary analysis tool used to identify and classify malware samples. It functions as a malware research framework that allows for the definition of file descriptions and detection rules to find indicators of compromise within binaries. The system enables the creation of custom detection rules using strings, wildcards, and regular expressions. These rules use boolean logic to match textual or binary patterns, allowing for the classification of files into specific malware families and the automation of threat intelligence. The engine utilizes Aho-Corasick s

    Cyara
    View on GitHub↗9,420
  • lordnoteworthy/al-khaserLordNoteworthy avatar

    LordNoteworthy/al-khaser

    7,001View on GitHub↗

    Al-Khaser is a research project focused on the development of anti-analysis and evasion techniques to resist reverse engineering. It provides implementations for detecting and evading virtual machines, sandboxes, and debuggers to prevent software analysis. The project implements control flow obfuscation through anti-disassembly methods and utilizes dynamic API resolution to bypass static import tables. It further hinders forensic analysis by manipulating memory headers to prevent process dumps and utilizing remote code injection to execute logic in external processes. The capability surface

    C++
    View on GitHub↗7,001

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • sbilly/awesome-securitysbilly avatar

    sbilly/awesome-security

    14,022View on GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    awesome-listsecurity
    View on GitHub↗14,022
  • a0rtega/pafisha0rtega avatar

    a0rtega/pafish

    3,920View on GitHub↗

    Pafish is an anti-analysis sandbox detector and virtualization environment tester. It serves as a diagnostic utility to identify if a system is running inside a virtual machine or a malware analysis sandbox by executing common anti-analysis techniques. The tool validates the effectiveness of various evasion methods and supports research into sandbox detection. It tests whether a target system can be recognized as a virtualized environment to help improve the stealth of malware analysis environments. Detection is achieved through a variety of behavioral checks, including hardware artifact ana

    C
    View on GitHub↗3,920
  • pan-unit42/iocspan-unit42 avatar

    pan-unit42/iocs

    727View on GitHub↗

    This repository contains indicators related to Unit 42 Public Reports.

    PHP
    View on GitHub↗727
  • neo23x0/signature-baseNeo23x0 avatar

    Neo23x0/signature-base

    2,975View on GitHub↗

    YARA signature and IOC database for my scanners and tools

    YARA
    View on GitHub↗2,975
  • reversinglabs/reversinglabs-yara-rulesreversinglabs avatar

    reversinglabs/reversinglabs-yara-rules

    922View on GitHub↗

    ReversingLabs YARA Rules

    YARA
    View on GitHub↗922
  • advanced-threat-research/yara-rulesadvanced-threat-research avatar

    advanced-threat-research/Yara-Rules

    626View on GitHub↗

    Repository of YARA rules made by Trellix ATR Team

    YARA
    View on GitHub↗626
  • rastrea2r/rastrea2rrastrea2r avatar

    rastrea2r/rastrea2r

    242View on GitHub↗

    Collecting & Hunting for IOCs with gusto and style

    Python
    View on GitHub↗242
  • advanced-threat-research/iocsadvanced-threat-research avatar

    advanced-threat-research/IOCs

    83View on GitHub↗

    Repository containing IOCs, CSV and MISP JSON from our blogs

    HTML
    View on GitHub↗83
  • inquest/yara-rulesInQuest avatar

    InQuest/yara-rules

    390View on GitHub↗

    A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.

    Python
    View on GitHub↗390
  • misp/mispMISP avatar

    MISP/MISP

    6,360View on GitHub↗

    MISP is an open-source threat intelligence sharing platform designed for collecting, storing, and distributing structured threat indicators and intelligence. At its core, it provides a distributed synchronization protocol for transferring events between instances, an attribute-based correlation engine that links matching indicators across events, and a REST API with an OpenAPI specification for programmatic access to threat data. The platform uses formal data formats for JSON, taxonomy, galaxy, and object templates to enable compatibility across tools and communities. The platform distinguish

    PHP
    View on GitHub↗6,360
  • inquest/threatingestorInQuest avatar

    InQuest/ThreatIngestor

    917View on GitHub↗

    Extract and aggregate threat intelligence.

    Python
    View on GitHub↗917
  • citizenlab/malware-signaturescitizenlab avatar

    citizenlab/malware-signatures

    143View on GitHub↗

    Yara rules for malware families seen as part of targeted threats project

    VimL
    View on GitHub↗143
  • kevthehermit/yararuleskevthehermit avatar

    kevthehermit/YaraRules

    52View on GitHub↗

    My Yara Rules Collection

    View on GitHub↗52
  • kevoreilly/capev2kevoreilly avatar

    kevoreilly/CAPEv2

    3,284View on GitHub↗

    Malware Configuration And Payload Extraction

    Python
    View on GitHub↗3,284
  • x64dbg/yarasigsx64dbg avatar

    x64dbg/yarasigs

    87View on GitHub↗

    Various Yara signatures (possibly to be included in a release later).

    YARA
    View on GitHub↗87
  • intezer/yara-rulesintezer avatar

    intezer/yara-rules

    131View on GitHub↗
    YARA
    View on GitHub↗131
  • comodosecurity/openedrComodoSecurity avatar

    ComodoSecurity/openedr

    2,603View on GitHub↗

    OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity. The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks. The platform provides capabi

    C++
    View on GitHub↗2,603
  • falcosecurity/falcofalcosecurity avatar

    falcosecurity/falco

    8,670View on GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    View on GitHub↗8,670
  • mandiant/flare-flossmandiant avatar

    mandiant/flare-floss

    3,886View on GitHub↗

    Flare-floss is a security utility and static binary string extractor designed to uncover hidden text and configuration data within compiled binaries. It functions as an obfuscated string decoder and reverse engineering tool to translate encoded strings into readable text for security auditing. The project employs emulated execution to capture the decrypted state of strings in memory by running small chunks of binary code in a virtual CPU. It further utilizes static analysis disassembly, intermediate representation analysis, and heuristic-based pattern matching to identify and decode strings t

    Pythondeobfuscationflaregsoc-2026
    View on GitHub↗3,886
  • owasp-modsecurity/modsecurityowasp-modsecurity avatar

    owasp-modsecurity/ModSecurity

    9,680View on GitHub↗

    ModSecurity is an open-source web application firewall and security engine. It functions as an HTTP traffic inspector and intrusion detection system that filters incoming web requests and responses against a set of security rules to block threats and prevent attacks on web servers. The project provides a modular framework for implementing restrictive security policies and custom filtering logic. It identifies and blocks common injection attacks, such as cross-site scripting and SQL injection, while hardening web applications to reduce their overall attack surface. Its broader capabilities in

    C++apacheapache2modsecurity
    View on GitHub↗9,680
  • security-onion-solutions/securityonionSecurity-Onion-Solutions avatar

    Security-Onion-Solutions/securityonion

    4,661View on GitHub↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    View on GitHub↗4,661
  • mantvydasb/redteaming-tactics-and-techniquesmantvydasb avatar

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620View on GitHub↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    View on GitHub↗4,620
  • de4dot/de4dotde4dot avatar

    de4dot/de4dot

    7,428View on GitHub↗

    de4dot is a .NET deobfuscator and unpacker designed to reverse obfuscation and restore readable code and metadata within .NET assemblies. It functions as a bytecode analyzer that simplifies control flow, strips anti-debugging protections, and extracts original payloads from packed executable wrappers. The project distinguishes itself through a modular deobfuscation pipeline and a sandbox environment used for dynamic string decryption, which executes decryption methods to replace encrypted strings with plain-text values. It can identify specific obfuscation tools through pattern-based binary a

    C#
    View on GitHub↗7,428
  • cilium/tetragoncilium avatar

    cilium/tetragon

    4,753View on GitHub↗

    Tetragon is an eBPF-based runtime security and observability toolset designed for Linux and Kubernetes environments. It functions as a security policy manager, observability agent, and enforcement engine that hooks into kernel functions and tracepoints to detect privilege escalation, container escapes, and unauthorized system activity. The project distinguishes itself through its ability to perform real-time, in-kernel enforcement, allowing it to synchronously terminate malicious processes or modify function return values before a system call completes. It provides deep Kubernetes integration

    C
    View on GitHub↗4,753
  • lolbas-project/lolbasLOLBAS-Project avatar

    LOLBAS-Project/LOLBAS

    8,323View on GitHub↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    View on GitHub↗8,323