30 open-source projects similar to citizenlab/malware-signatures, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Malware Signatures alternative.
Repository of YARA rules made by Trellix ATR Team
ReversingLabs YARA Rules
Various Yara signatures (possibly to be included in a release later).
This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious patterns in files. It serves as a dataset of signatures for identifying known malware families, software packers, and threat intelligence indicators. The collection provides specialized detection capabilities for identifying exploit kits and anti-analysis evasion techniques, such as anti-debugging and anti-virtualization methods. It also includes signatures for cryptographic algorithm detection and the identification of unauthorized remote administration tools on servers. The r
A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.
YARA is a pattern matching engine and binary analysis tool used to identify and classify malware samples. It functions as a malware research framework that allows for the definition of file descriptions and detection rules to find indicators of compromise within binaries. The system enables the creation of custom detection rules using strings, wildcards, and regular expressions. These rules use boolean logic to match textual or binary patterns, allowing for the classification of files into specific malware families and the automation of threat intelligence. The engine utilizes Aho-Corasick s
A home for detection content developed by the delivr.to team
rules to identify files containing juicy information like usernames, passwords etc
Please no pull requests for this repository. Thanks!
Detection in the form of Yara, Snort and ClamAV signatures.
Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malicious artifacts.
Public catalog of stealer log fingerprints. Banner strings, field signatures, sanitized samples, and YARA rules for 30+ malware families including RedLine, Vidar, Lumma, StealC, and Rhadamanthys. For incident response, detection engineering, and threat intelligence research.
Alienvault Labs Projects Random Stuff
A collection of curated YARA rules used as part of the Filescan.io service
This repository regroups the Yara Rules for the Unprotect Project
Yara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies
Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X, machine learning AI, behavioral analysis, Unpacker, Deobfuscator, Decompiler, website signatures, Ghidra, Suricata, Sigma, Kernel, Hypervisior based protection and much more than you can imagine.
Indicators of Compromises (IOC) of our various investigations
Yara rules to be used with the Burp Yara-Scanner extension
A collection of my public YARA signatures for various malware families