For 恶意软件检测规则工具包, the strongest matches are cystack/stealer-fingerprints (This repository delivers exactly what you need: a public), neo23x0/signature-base (neo23x0/signature-base is a repository of YARA signatures and IOCs) and elastic/protections-artifacts (Elastic's protections-artifacts repository provides a comprehensive, pre-written set of). eset/malware-ioc and yara-rules/rules round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
旨在识别和分析特定恶意软件家族特征的 YARA 规则集集合。
Public catalog of stealer log fingerprints. Banner strings, field signatures, sanitized samples, and YARA rules for 30+ malware families including RedLine, Vidar, Lumma, StealC, and Rhadamanthys. For incident response, detection engineering, and threat intelligence research.
This repository delivers exactly what you need: a public catalog of YARA rules for 30+ stealer malware families (RedLine, Vidar, Lumma, etc.), built for incident response and detection engineering, with community-contributed fingerprints and field signatures.
YARA signature and IOC database for my scanners and tools
neo23x0/signature-base is a repository of YARA signatures and IOCs, giving you pre-written rules for malware detection and integration with threat intelligence feeds, which directly matches the search for a YARA rule repository.
Elastic Security detection content for Endpoint
Elastic's protections-artifacts repository provides a comprehensive, pre-written set of YARA rules for endpoint malware detection, backed by Elastic's security research and community contributions, which exactly matches your need for a YARA rule collection with community involvement.
Indicators of Compromises (IOC) of our various investigations
ESET's malware-ioc repository provides YARA rules and indicators of compromise from their investigations, making it a relevant source of pre-written malware family rules for YARA-based detection.
This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r
This repository is a community-curated collection of YARA rules for detecting malware, webshells, and other malicious patterns, which directly matches the request for pre-written rules with community contributions and threat intelligence integration.
Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.
anyrun/yara is a community-maintained collection of YARA rules targeting malware families from the ANY.RUN team, directly matching the request for pre-written detection rules, though it does not explicitly include rule testing tools or malware feed integration.
Collection of private Yara rules.
This repository is a private collection of YARA rules for malware detection, fitting the request for a rule repository, but as a single-author collection it may be less comprehensive than larger community-driven rule sets and lacks built-in testing or feed integration.
This repository contains GCTI's open source detection signatures.
GCTI’s repository provides ready-made YARA detection signatures for malware families from Google Cloud Threat Intelligence, which directly fits the need for a community-oriented YARA rule repository, though it lacks built-in testing or feed integration.
Collection of YARA signatures from individual research
deadbits/yara-rules is a repository of YARA signatures from individual research, providing pre-written malware detection rules that directly match your need for YARA rulesets, though it lacks built-in testing/validation or feed integration features.
A home for detection content developed by the delivr.to team
A YARA rule collection from the delivr.to team, matching the request for a repository of detection rules, though it lacks explicit rule testing/validation or malware feed integration features.
Detection in the form of Yara, Snort and ClamAV signatures.
This repository contains YARA signatures alongside Snort and ClamAV rules, making it a valid YARA rule repository for malware detection, though it does not explicitly provide rule testing or feed integration.
Some YARA rules i will add from time to time
This is a personal collection of YARA rules from a single author, which fits as a repository of malware detection rules but lacks community contributions, testing tools, or integration with threat feeds.
This repository is tagged as a YARA rule collection, making it directly relevant for finding pre-written malware detection rules, though the empty description means its exact scope and features are unconfirmed.
A collection of curated YARA rules used as part of the Filescan.io service
A curated collection of YARA rules from the Filescan.io service, giving you pre-written detection rules for malware families, though it is a service-specific set rather than a broad community repository.
Repository of YARA rules made by Trellix ATR Team
This is a dedicated collection of YARA rules from the Trellix ATR team, directly targeting malware detection with pre-written rules, fitting the search for a YARA rule repository for detecting specific malware families.
Yara rules for malware families seen as part of targeted threats project
This repository contains YARA rules written for malware families tracked by the Citizen Lab's targeted threats project, giving you pre-written detection signatures that directly match the request for malware-specific rulesets.
Yara rules to be used with the Burp Yara-Scanner extension
This repository is a collection of YARA rules designed for the Burp Yara-Scanner extension, so it fits the YARA rule repository category, but the rules are focused on passive web scanning rather than the broad malware-family detection you are seeking.
My Yara Rules Collection
This repository is a collection of YARA rules for malware detection, matching your need for pre-written rules even though it does not include built-in testing tools or feed integration.
yarGen is a generator for YARA rules
yarGen is a generator for creating YARA rules from strings in malicious files, making it a helpful tool for rule creation but not a repository of pre-written malware family rules.
| 仓库 | Star 数 | 语言 | 许可证 | 最后推送 |
|---|---|---|---|---|
| cystack/stealer-fingerprints | 2 | YARA | Apache-2.0 | |
| neo23x0/signature-base | 3K | YARA | NOASSERTION | |
| elastic/protections-artifacts | 1.4K | YARA | NOASSERTION | |
| eset/malware-ioc | 2K | YARA | BSD-2-Clause | |
| yara-rules/rules | 4.7K | YARA | gpl-2.0 | |
| anyrun/yara | 29 | YARA | — | |
| bartblaze/yara-rules | 385 | YARA | MIT | |
| chronicle/gcti | 553 | YARA | Apache-2.0 | |
| deadbits/yara-rules | 44 | YARA | Unlicense | |
| delivr-to/detections | 75 | YARA | — |