awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

YARA 恶意软件检测规则

排名更新于 2026年6月30日

For 恶意软件检测规则工具包, the strongest matches are cystack/stealer-fingerprints (This repository delivers exactly what you need: a public), neo23x0/signature-base (neo23x0/signature-base is a repository of YARA signatures and IOCs) and elastic/protections-artifacts (Elastic's protections-artifacts repository provides a comprehensive, pre-written set of). eset/malware-ioc and yara-rules/rules round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

旨在识别和分析特定恶意软件家族特征的 YARA 规则集集合。

YARA 恶意软件检测规则

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • cystack/stealer-fingerprintscystack 的头像

    cystack/stealer-fingerprints

    2在 GitHub 上查看↗

    Public catalog of stealer log fingerprints. Banner strings, field signatures, sanitized samples, and YARA rules for 30+ malware families including RedLine, Vidar, Lumma, StealC, and Rhadamanthys. For incident response, detection engineering, and threat intelligence research.

    This repository delivers exactly what you need: a public catalog of YARA rules for 30+ stealer malware families (RedLine, Vidar, Lumma, etc.), built for incident response and detection engineering, with community-contributed fingerprints and field signatures.

    YARAYara Rule Collections
    在 GitHub 上查看↗2
  • neo23x0/signature-baseNeo23x0 的头像

    Neo23x0/signature-base

    2,975在 GitHub 上查看↗

    YARA signature and IOC database for my scanners and tools

    neo23x0/signature-base is a repository of YARA signatures and IOCs, giving you pre-written rules for malware detection and integration with threat intelligence feeds, which directly matches the search for a YARA rule repository.

    YARAYara Rule CollectionsThreat Intelligence Feeds
    在 GitHub 上查看↗2,975
  • elastic/protections-artifactselastic 的头像

    elastic/protections-artifacts

    1,441在 GitHub 上查看↗

    Elastic Security detection content for Endpoint

    Elastic's protections-artifacts repository provides a comprehensive, pre-written set of YARA rules for endpoint malware detection, backed by Elastic's security research and community contributions, which exactly matches your need for a YARA rule collection with community involvement.

    YARAYara Rule Collections
    在 GitHub 上查看↗1,441
  • eset/malware-ioceset 的头像

    eset/malware-ioc

    1,955在 GitHub 上查看↗

    Indicators of Compromises (IOC) of our various investigations

    ESET's malware-ioc repository provides YARA rules and indicators of compromise from their investigations, making it a relevant source of pre-written malware family rules for YARA-based detection.

    YARAYara Rule CollectionsThreat Intelligence Feeds
    在 GitHub 上查看↗1,955
  • yara-rules/rulesYara-Rules 的头像

    Yara-Rules/rules

    4,712在 GitHub 上查看↗

    This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r

    This repository is a community-curated collection of YARA rules for detecting malware, webshells, and other malicious patterns, which directly matches the request for pre-written rules with community contributions and threat intelligence integration.

    YARAMalware Family IdentificationYara Rule CollectionsThreat Intelligence Feeds
    在 GitHub 上查看↗4,712
  • anyrun/yaraanyrun 的头像

    anyrun/YARA

    29在 GitHub 上查看↗

    Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.

    anyrun/yara is a community-maintained collection of YARA rules targeting malware families from the ANY.RUN team, directly matching the request for pre-written detection rules, though it does not explicitly include rule testing tools or malware feed integration.

    YARAYara Rule Collections
    在 GitHub 上查看↗29
  • bartblaze/yara-rulesbartblaze 的头像

    bartblaze/Yara-rules

    385在 GitHub 上查看↗

    Collection of private Yara rules.

    This repository is a private collection of YARA rules for malware detection, fitting the request for a rule repository, but as a single-author collection it may be less comprehensive than larger community-driven rule sets and lacks built-in testing or feed integration.

    YARAYara Rule Collections
    在 GitHub 上查看↗385
  • chronicle/gctichronicle 的头像

    chronicle/GCTI

    553在 GitHub 上查看↗

    This repository contains GCTI's open source detection signatures.

    GCTI’s repository provides ready-made YARA detection signatures for malware families from Google Cloud Threat Intelligence, which directly fits the need for a community-oriented YARA rule repository, though it lacks built-in testing or feed integration.

    YARAYara Rule Collections
    在 GitHub 上查看↗553
  • deadbits/yara-rulesdeadbits 的头像

    deadbits/yara-rules

    44在 GitHub 上查看↗

    Collection of YARA signatures from individual research

    deadbits/yara-rules is a repository of YARA signatures from individual research, providing pre-written malware detection rules that directly match your need for YARA rulesets, though it lacks built-in testing/validation or feed integration features.

    YARAYara Rule Collections
    在 GitHub 上查看↗44
  • delivr-to/detectionsdelivr-to 的头像

    delivr-to/detections

    75在 GitHub 上查看↗

    A home for detection content developed by the delivr.to team

    A YARA rule collection from the delivr.to team, matching the request for a repository of detection rules, though it lacks explicit rule testing/validation or malware feed integration features.

    YARAYara Rule Collections
    在 GitHub 上查看↗75
  • ditekshen/detectionditekshen 的头像

    ditekshen/detection

    254在 GitHub 上查看↗

    Detection in the form of Yara, Snort and ClamAV signatures.

    This repository contains YARA signatures alongside Snort and ClamAV rules, making it a valid YARA rule repository for malware detection, though it does not explicitly provide rule testing or feed integration.

    YARAYara Rule Collections
    在 GitHub 上查看↗254
  • fboldewin/yara-rulesfboldewin 的头像

    fboldewin/YARA-rules

    70在 GitHub 上查看↗

    Some YARA rules i will add from time to time

    This is a personal collection of YARA rules from a single author, which fits as a repository of malware detection rules but lacks community contributions, testing tools, or integration with threat feeds.

    YARAYara Rule Collections
    在 GitHub 上查看↗70
  • fideliscyber/indicatorsF

    fideliscyber/indicators

    0在 GitHub 上查看↗

    This repository is tagged as a YARA rule collection, making it directly relevant for finding pre-written malware detection rules, though the empty description means its exact scope and features are unconfirmed.

    Yara Rule Collections
    在 GitHub 上查看↗0
  • filescanio/fsyarafilescanio 的头像

    filescanio/fsYara

    22在 GitHub 上查看↗

    A collection of curated YARA rules used as part of the Filescan.io service

    A curated collection of YARA rules from the Filescan.io service, giving you pre-written detection rules for malware families, though it is a service-specific set rather than a broad community repository.

    YARAYara Rule Collections
    在 GitHub 上查看↗22
  • advanced-threat-research/yara-rulesadvanced-threat-research 的头像

    advanced-threat-research/Yara-Rules

    626在 GitHub 上查看↗

    Repository of YARA rules made by Trellix ATR Team

    This is a dedicated collection of YARA rules from the Trellix ATR team, directly targeting malware detection with pre-written rules, fitting the search for a YARA rule repository for detecting specific malware families.

    YARAYara Rule Collections
    在 GitHub 上查看↗626
  • citizenlab/malware-signaturescitizenlab 的头像

    citizenlab/malware-signatures

    143在 GitHub 上查看↗

    Yara rules for malware families seen as part of targeted threats project

    This repository contains YARA rules written for malware families tracked by the Citizen Lab's targeted threats project, giving you pre-written detection signatures that directly match the request for malware-specific rulesets.

    VimLYara Rule Collections
    在 GitHub 上查看↗143
  • codewatchorg/burp-yara-rulescodewatchorg 的头像

    codewatchorg/Burp-Yara-Rules

    49在 GitHub 上查看↗

    Yara rules to be used with the Burp Yara-Scanner extension

    This repository is a collection of YARA rules designed for the Burp Yara-Scanner extension, so it fits the YARA rule repository category, but the rules are focused on passive web scanning rather than the broad malware-family detection you are seeking.

    YARAYara Rule Collections
    在 GitHub 上查看↗49
  • kevthehermit/yararuleskevthehermit 的头像

    kevthehermit/YaraRules

    52在 GitHub 上查看↗

    My Yara Rules Collection

    This repository is a collection of YARA rules for malware detection, matching your need for pre-written rules even though it does not include built-in testing tools or feed integration.

    Yara Rule Collections
    在 GitHub 上查看↗52
  • neo23x0/yargenNeo23x0 的头像

    Neo23x0/yarGen

    1,796在 GitHub 上查看↗

    yarGen is a generator for YARA rules

    yarGen is a generator for creating YARA rules from strings in malicious files, making it a helpful tool for rule creation but not a repository of pre-written malware family rules.

    PythonYara Rules
    在 GitHub 上查看↗1,796
一览前 10 名对比
仓库Star 数语言许可证最后推送
cystack/stealer-fingerprints2YARAApache-2.02026年6月9日
neo23x0/signature-base3KYARANOASSERTION2026年6月15日
elastic/protections-artifacts1.4KYARANOASSERTION2026年6月8日
eset/malware-ioc2KYARABSD-2-Clause2026年6月16日
yara-rules/rules4.7KYARAgpl-2.02024年4月16日
anyrun/yara29YARA—2025年11月1日
bartblaze/yara-rules385YARAMIT2026年1月28日
chronicle/gcti553YARAApache-2.02023年12月4日
deadbits/yara-rules44YARAUnlicense2023年11月20日
delivr-to/detections75YARA—2025年8月10日

Related searches

  • 代码即检测 (Detection-as-Code) 规则集
  • 恶意软件分析与逆向工程
  • 二进制脱壳工具包
  • 取证分类工具
  • 用于系统防护的开源杀毒软件
  • 代码敏感信息检测工具
  • 恶意软件分析沙箱
  • 文件雕刻与恢复工具