.. |
apt_aa19_024a.yar
|
APT DNS Hijacking campaign AA19-024A
|
2019-01-29 15:31:54 +01:00 |
apt_agent_btz.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_alienspy_rat.yar
|
False Positives
|
2017-05-25 11:36:50 +02:00 |
apt_apt6_malware.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt10_redleaves.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt10.yar
|
fix: missing "pe" import
|
2018-12-29 09:20:24 +01:00 |
apt_apt12_malware.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt15.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt17_mal_sep17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt17_malware.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt19.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt28.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt29_grizzly_steppe.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt30_backspace.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_apt34.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ar18_165a.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_area1_phishing_diplomacy.yar
|
Area1 Phishing Diplomacy Rules
|
2018-12-19 19:17:51 +01:00 |
apt_backdoor_ssh_python.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_backspace.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_beepservice.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_between-hk-and-burma.yar
|
Adjusted SLServer Rule
|
2016-04-21 11:03:55 +02:00 |
apt_bigbang.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_blackenergy_installer.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_blackenergy.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_bluetermite_emdivi.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_bronze_butler.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_buckeye.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_carbon_paper_turla.yar
|
Carbon - Turla - rules by ESET
|
2017-04-01 11:56:20 +02:00 |
apt_casper.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_cheshirecat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_cloudduke.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_cmstar.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_cn_pp_zerot.yar
|
False Positive Reduction
|
2018-09-24 12:30:09 +02:00 |
apt_cobaltstrike.yar
|
JPCERT CobaltStrike beacon rule
|
2018-11-09 08:27:38 +01:00 |
apt_codoso.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_coreimpact_agent.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_danti_svcmondr.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_darkcaracal.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_darkhydrus.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_deeppanda.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_derusbi.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_dnspionage.yar
|
Rule improvements
|
2019-02-02 17:14:44 +01:00 |
apt_donotteam_ytyframework.yar
|
Minor changes and adjustments
|
2018-06-22 00:00:14 +02:00 |
apt_dragonfly.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_dubnium.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_duqu2.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_emissary.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_eqgrp_apr17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_eqgrp.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_eternalblue_non_wannacry.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_exile_rat.yar
|
ExileRAT
|
2019-02-04 20:44:06 +01:00 |
apt_fakem_backdoor.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fancybear_computrace_agent.yar
|
Renamed Rule
|
2018-05-20 18:49:45 +02:00 |
apt_fancybear_dnc.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fancybear_osxagent.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fidelis_phishing_plain_sight.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fin7_backdoor.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fin7.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_foudre.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_four_element_sword.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_freemilk.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_furtim.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fvey_shadowbroker_dec16.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_fvey_shadowbroker_jan17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ghostdragon_gh0st_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_glassRAT.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_golddragon.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_greenbug.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_greyenergy.yar
|
Grey Energy
|
2018-10-22 00:40:07 +02:00 |
apt_grizzlybear_uscert.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_hackingteam_rules.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ham_tofu_chches.yar
|
False Positives
|
2017-03-28 08:32:20 +02:00 |
apt_hatman.yar
|
Disabled global rule to avoid the application in the concatenated rule set
|
2017-12-19 01:37:49 +01:00 |
apt_hellsing_kaspersky.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_hidden_cobra.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_hiddencobra_bankshot.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_hiddencobra_wiper.yar
|
Hidden Cobra Wiper
|
2018-03-28 19:57:12 +02:00 |
apt_hizor_rat.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_hkdoor.yar
|
Replaced non-ASCII character
|
2017-10-19 01:17:59 +02:00 |
apt_icefog.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_indetectables_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_industroyer.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_inocnation.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_irongate.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_irontiger_trendmicro.yar
|
Moved all rules that use ext vars to a new rule set
|
2018-03-12 13:47:40 +01:00 |
apt_irontiger.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ism_rat.yar
|
ISMRAT
|
2017-05-04 12:22:58 +02:00 |
apt_kaspersky_duqu2.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_keyboys.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_keylogger_cn.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_khrat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_korplug_fast.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_kwampirs.yar
|
Kwampirs malware
|
2018-04-24 11:29:01 +02:00 |
apt_laudanum_webshells.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_lazarus_applejeus.yar
|
Fixed error in RC4 keys list
|
2018-08-26 20:16:40 +02:00 |
apt_lazarus_dec17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_lazarus_jun18.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_leviathan.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_lotusblossom_elise.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_magichound.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_microcin.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_middle_east_talosreport.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_miniasp.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_minidionis.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_mofang.yar
|
FoxIT Mofang IOCs and YARA Rules
|
2016-06-15 18:58:10 +02:00 |
apt_molerats_jul17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_monsoon.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_moonlightmaze.yar
|
False Positive Reduction
|
2017-12-19 01:36:08 +01:00 |
apt_ms_platinum.yara
|
Microsoft Platinum YARA Rules
|
2016-04-27 13:36:39 +02:00 |
apt_muddywater.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_naikon.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_nanocore_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ncsc_report_04_2018.yar
|
Rule improvements
|
2018-04-11 23:51:43 +02:00 |
apt_netwire_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_oilrig_chafer_mar18.yar
|
OilRig / Chafer YARA Rules
|
2018-03-23 08:43:43 +01:00 |
apt_oilrig_oct17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_oilrig_rgdoor.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_oilrig.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_olympic_destroyer.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_onhat_proxy.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_op_cleaver.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_op_cloudhopper.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_op_honeybee.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_passcv.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_passthehashtoolkit.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_plead_downloader.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_plugx.yar
|
PlugX Signature by Jay DiMartino
|
2016-08-17 13:20:52 +02:00 |
apt_poisonivy_gen3.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_poisonivy.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_poseidon_group.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_poshspy.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_prikormka.yar
|
Bugfix in prikormka Rules
|
2016-06-17 17:24:28 +02:00 |
apt_project_m.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_project_sauron_extras.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_project_sauron.yara
|
Project Sauron
|
2016-08-08 17:11:20 +02:00 |
apt_promethium_neodymium.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_putterpanda.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_quarkspwdump.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_quasar_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_quasar_vermin.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_rancor.yar
|
YARA rule description cleanup
|
2018-12-28 12:38:31 +01:00 |
apt_reaver_sunorcal.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_rehashed_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_revenge_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_rocketkitten_keylogger.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_rokrat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ruag.yar
|
RUAG APT Case YARA Signatures
|
2016-05-24 07:29:20 -06:00 |
apt_rwmc_powershell_creddump.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sakula.yar
|
Turla Rules - RUAG APT
|
2016-06-13 10:41:59 +02:00 |
apt_saudi_aramco_phish.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_scanbox_deeppanda.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_scarcruft.yar
|
Scracruft APT malware
|
2018-02-05 10:22:40 +01:00 |
apt_seaduke_unit42.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sednit_delphidownloader.yar
|
False Positive Reduction
|
2019-01-17 13:12:39 +01:00 |
apt_servantshell.yar
|
Servant Shell
|
2017-02-07 10:37:26 +01:00 |
apt_shadowpad.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_shamoon2.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_shamoon.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_shellcrew_streamex.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_silence.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_skeletonkey.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_slingshot.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_snaketurla_osx.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_snowglobe_babar.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sofacy_cannon.yar
|
APT28 Cannon Trojan
|
2018-11-21 21:29:31 +01:00 |
apt_sofacy_dec15.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sofacy_fysbis.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sofacy_hospitality.yar
|
Missing "pe" module import in APT28 rule
|
2017-10-31 11:29:48 +01:00 |
apt_sofacy_jun16.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sofacy_oct17_camp.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sofacy_xtunnel_bundestag.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sofacy_zebrocy.yar
|
APT28 Zebrocy Golang Loader by @VK_Intel
|
2019-01-02 09:19:09 +01:00 |
apt_sofacy.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sphinx_moth.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_stonedrill.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_strider.yara
|
Symantec Strider IOCs and YARA Rules
|
2016-08-10 09:33:54 +02:00 |
apt_stuxnet.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_suckfly.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_sysscan.yar
|
SysScan Rules by Kaspersky
|
2016-07-02 19:32:36 +02:00 |
apt_ta17_293A.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ta17_318A.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ta17_318B.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ta18_074A.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ta18_149A.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_ta459.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_telebots.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_terracotta_liudoor.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_terracotta.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_threatgroup_3390.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_thrip.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_tick_datper.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_tick_weaponized_usb.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_tidepool.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_tophat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_triton_mal_sshdoor.yar
|
fix: bugfix in SSHDoor rule - missing "and"
|
2018-12-05 21:03:24 +01:00 |
apt_triton.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_turbo_campaign.yar
|
Derusbi ELF / Win32 Turbo Campaign
|
2016-02-29 20:32:42 +01:00 |
apt_turla_gazer.yar
|
APT Turla Gazer
|
2017-09-02 08:26:07 +02:00 |
apt_turla_mosquito.yar
|
False Positive Reduction
|
2018-10-10 16:30:08 +02:00 |
apt_turla_neuron.yar
|
False Positive Reduction
|
2019-01-20 17:36:18 +01:00 |
apt_turla_png_dropper_nov18.yar
|
fix: missing pe import
|
2018-11-23 08:38:19 +01:00 |
apt_turla.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_uboat_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_unit78020_malware.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_uscert_ta17-1117a.yar
|
fix: moved lsadump rule from general rules to the ext vars file
|
2019-01-19 12:22:32 +01:00 |
apt_venom_linux_rootkit.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_volatile_cedar.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_vpnfilter.yar
|
YARA rule description cleanup
|
2018-12-28 12:38:31 +01:00 |
apt_waterbear.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_waterbug.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
apt_webmonitor_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_webshell_chinachopper.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_wildneutron.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_wilted_tulip.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_win_plugx.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_winnti_burning_umbrella.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_winnti_hdroot.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_winnti_ms_report_201701.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_winnti.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_woolengoldfish.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_xrat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
apt_zxshell.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
cn_pentestset_scripts.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
cn_pentestset_tools.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
cn_pentestset_webshells.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_andromeda_jun17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_antifw_installrex.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_bad_patch.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_badrabbit.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_bernhard_pos.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
crime_bluenoroff_pos.yar
|
BluenoroffPoS DLL
|
2018-06-08 21:12:24 +02:00 |
crime_buzus_softpulse.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_cmstar.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
crime_cn_campaign_njrat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_cn_group_btc.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_cobalt_gang_pdf.yar
|
Cobalt Gang Rule by PaloAltoNetwroks
|
2018-10-30 09:17:04 +01:00 |
crime_cobaltgang.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_corkow_dll.yar
|
Missing PE module imports, minor changes
|
2017-10-11 18:43:19 +02:00 |
crime_credstealer_generic.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_cryptowall_svg.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_dexter_trojan.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_dridex_xml.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
crime_enfal.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_envrial.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_eternalrocks.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_fareit.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_fireball.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_floxif_flystudio.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_goldeneye.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_hermes_ransom.yar
|
FEIB Report - by BEA systems
|
2017-10-17 08:31:59 +02:00 |
crime_kasper_oct17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_kins_dropper.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
crime_kr_malware.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_kraken_bot1.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_kriskynote.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_locky.yar
|
Locky Ransomware
|
2016-02-17 18:03:58 +01:00 |
crime_loki_bot.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_mal_grandcrab.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_mal_nitol.yar
|
Nitol Malware
|
2019-01-14 11:20:18 +01:00 |
crime_malumpos.yar
|
Moved all rules that use ext vars to a new rule set
|
2018-03-12 13:47:40 +01:00 |
crime_malware_generic.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_malware_set_oct16.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_mikey_trojan.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_mirai.yar
|
Updated Mirai rules
|
2018-10-27 21:58:34 +02:00 |
crime_mywscript_dropper.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_nkminer.yar
|
North Korean Crypto Miner (by Chris Doman and me)
|
2018-01-10 08:36:13 +01:00 |
crime_nopetya_jun17.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_ole_loadswf_cve_2018_4878.yar
|
OLE LoadSwf CVE 2018-4878
|
2018-02-05 10:20:19 +01:00 |
crime_phish_gina_dec15.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_rombertik_carbongrabber.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_ryuk_ransomware.yar
|
Ryuk Ransomware
|
2018-12-31 14:56:56 +01:00 |
crime_shifu_trojan.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_snarasite.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_teledoor.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_upatre_oct15.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_wannacry.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
crime_xbash.yar
|
Xbash
|
2018-09-20 07:38:08 +02:00 |
crime_zeus_panda.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2014_4076.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2015_1674.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2015_1701.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2015_2426.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2015_2545.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2015_5119.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2017_8759.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2017_9800.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2017_11882.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
exploit_cve_2018_0802.yar
|
YARA rule for CVE-2018-0802 by Rich Warren
|
2018-01-14 13:49:53 +01:00 |
exploit_cve_2018_16858.yar
|
Changed filename
|
2019-02-07 09:48:08 +01:00 |
exploit_rtf_ole2link.yar
|
Moved all rules that use ext vars to a new rule set
|
2018-03-12 13:47:40 +01:00 |
exploit_uac_elevators.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_ace_with_exe.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
gen_armitage.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_b374k_extra.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_bad_pdf.yar
|
Update gen_bad_pdf.yar
|
2019-01-10 11:28:31 +01:00 |
gen_case_anomalies.yar
|
False Positive Reduction
|
2019-01-17 13:12:39 +01:00 |
gen_cert_payloads.yar
|
False Positive Reduction
|
2018-08-21 10:58:45 +02:00 |
gen_chaos_payload.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_cn_hacktool_scripts.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_cn_hacktools.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_cn_webshells.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_crimson_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_crunchrat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_dde_in_office_docs.yar
|
False Positive Reduction
|
2019-01-20 17:36:18 +01:00 |
gen_deviceguard_evasion.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_dropper_pdb.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_elf_file_anomalies.yar
|
False Positive Reduction
|
2019-01-24 11:03:01 +01:00 |
gen_empire.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_enigma_protector.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_exploit_cve_2017_10271_weblogic.yar
|
update for VT uploads that include the POST header
|
2018-03-28 05:31:01 -07:00 |
gen_faked_versions.yar
|
Moved all rules that use ext vars to a new rule set
|
2018-03-12 13:47:40 +01:00 |
gen_floxif.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_gen_cactustorch.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_gpp_cpassword.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_hawkeye.yar
|
New HawkEye keylogger rule
|
2018-12-12 09:24:12 +01:00 |
gen_hta_anomalies.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_impacket_tools.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_invoke_mimikatz.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_invoke_psimage.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_invoke_thehash.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_javascript_powershell.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_kerberoast.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_kirbi_mimkatz.yar
|
Bugfixes and False Positive Reduction
|
2017-07-20 12:24:49 -06:00 |
gen_loaders.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_macro_ShellExecute_action.yar
|
Update gen_macro_ShellExecute_action.yar
|
2019-01-31 19:38:50 -08:00 |
gen_macro_staroffice_suspicious.yar
|
Minor changes
|
2019-02-07 18:09:34 +01:00 |
gen_mal_backnet.yar
|
Backnet Open Source C# backdoor
|
2018-11-09 08:27:53 +01:00 |
gen_mal_link.yar
|
False Positive Reduction
|
2019-01-17 13:12:39 +01:00 |
gen_mal_scripts.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_malware_MacOS_plist_suspicious.yar
|
Minor adjustments in gen_malware_MacOS_plist_suspicious rule
|
2018-12-16 10:10:42 +01:00 |
gen_malware_set_qa.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_merlin_agent.yar
|
Typo in Merlin rule
|
2017-12-29 15:15:57 +01:00 |
gen_metasploit_loader_rsmudge.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_metasploit_payloads.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_mimikittenz.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_mimipenguin.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_nopowershell.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_osx_backdoor_bella.yar
|
OSX malware by @JohnLaTwC
|
2018-02-24 10:08:40 +01:00 |
gen_osx_evilosx.yar
|
OSX malware by @JohnLaTwC
|
2018-02-24 10:08:40 +01:00 |
gen_osx_pyagent_persistence.yar
|
OSX malware by @JohnLaTwC
|
2018-02-24 10:08:40 +01:00 |
gen_p0wnshell.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_pirpi.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_powerkatz.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_powershdll.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_powershell_empire.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_powershell_invocation.yar
|
bugfix: PowerShell_Susp_Parameter_Combo
|
2019-01-17 13:18:07 +01:00 |
gen_powershell_obfuscation.yar
|
Rule: Powershell Obfuscation
|
2018-12-13 14:25:01 +01:00 |
gen_powershell_suite.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_powershell_susp.yar
|
False Positive Reduction and Cleanup
|
2018-12-11 15:08:39 +01:00 |
gen_powershell_toolkit.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_powersploit_dropper.yar
|
Hacktool PowerSploit Dropper
|
2018-06-24 22:44:28 +02:00 |
gen_ps1_shellcode.yar
|
Added David to the authors
|
2018-11-15 17:25:58 +01:00 |
gen_ps_empire_eval.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_ps_osiris.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_pua.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_pupy_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_python_encoded_adware
|
yara rule for encoded python payloads for adware
|
2018-03-07 08:45:57 -08:00 |
gen_python_reverse_shell.yara
|
Minor changes: performance reasons, reference, hashes split up
|
2018-03-05 15:41:51 +01:00 |
gen_rats_malwareconfig.yar
|
New JRAT rule
|
2018-11-09 08:28:05 +01:00 |
gen_recon_keywords.yar
|
False Positive Reduction
|
2019-01-17 13:12:39 +01:00 |
gen_redsails.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_regsrv32_issue.yar
|
Moved all rules that use ext vars to a new rule set
|
2018-03-12 13:47:40 +01:00 |
gen_rottenpotato.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_sfx_with_microsoft_copyright.yar
|
Fix: tightened the SFX rule
|
2018-09-17 08:27:58 +02:00 |
gen_sharpcat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_susp_cmd_var_expansion.yar
|
Suspicious CMD Var expansion in Office Docs
|
2018-09-28 13:29:35 +02:00 |
gen_susp_lnk_files.yar
|
Extended suspicious LNK file content rule
|
2019-02-05 09:11:33 +01:00 |
gen_susp_lnk.yar
|
Suspicious big LNK file
|
2019-02-05 09:11:16 +01:00 |
gen_susp_office_dropper.yar
|
Suspicious Office Droppers
|
2018-11-21 11:18:05 +01:00 |
gen_susp_sfx.yar
|
Suspicious SFX running wscript.exe
|
2018-09-28 13:29:43 +02:00 |
gen_susp_strings_in_ole.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_suspicious_strings.yar
|
JAVA class with VBS content
|
2019-01-07 13:28:06 +01:00 |
gen_sysinternals_anomaly.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_tempracer.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_thumbs_cloaking.yar
|
Moved all rules that use ext vars to a new rule set
|
2018-03-12 13:47:40 +01:00 |
gen_transformed_strings.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_tscookie_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_unicorn_obfuscated_powershell.yar
|
Performance optimization
|
2018-04-03 15:30:23 +02:00 |
gen_unspecified_malware.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_url_to_local_exe.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_win_privesc.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_winpayloads.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_winshells.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_wmi_implant.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_xtreme_rat.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
gen_ysoserial_payloads.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
general_cloaking.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
general_officemacros.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
generic_anomalies.yar
|
Kitty Fork Putty FP
|
2019-01-29 15:31:54 +01:00 |
generic_cryptors.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
generic_dumps.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
generic_exe2hex_payload.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
mal_cryp_rat.yar
|
Cryp RAT
|
2019-01-08 09:18:45 +01:00 |
pua_cryptocoin_miner.yar
|
New Crypto Coin miner rule
|
2019-02-02 17:14:44 +01:00 |
pua_xmrig_monero_miner.yar
|
Moved NK miner to generic list
|
2018-12-29 09:31:57 +01:00 |
pup_lightftp.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
spy_equation_fiveeyes.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
spy_querty_fiveeyes.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
spy_regin_fiveeyes.yar
|
License notice on my own rules, removed rules with unclear/problematic licensing
|
2018-08-26 12:48:01 +02:00 |
SUSP_autocad_lsp_malware.yar
|
0x28 is subset of other condition
|
2019-02-11 15:13:47 +01:00 |
thor_inverse_matches.yar
|
Added LOKI / SPARK specific rule to thor's inverse set
|
2018-11-15 09:23:01 +01:00 |
thor-hacktools.yar
|
Suspicious Katz.PDB
|
2019-02-05 09:11:43 +01:00 |
thor-webshells.yar
|
I'd adjust it like that
|
2019-01-16 19:27:29 +01:00 |
threat_lenovo_superfish.yar
|
signatures > yara
|
2016-02-15 12:31:27 +01:00 |
vul_drivecrypt.yar
|
Renamed DriveCrypt rule
|
2018-11-09 08:28:21 +01:00 |
vul_jquery_fileupload_cve_2018_9206.yar
|
jQuery File Upload Vulnerability
|
2018-10-19 09:07:37 +02:00 |
yara_mixed_ext_vars.yar
|
fix: moved lsadump rule from general rules to the ext vars file
|
2019-01-19 12:22:32 +01:00 |