Mquery is an analyst-friendly web GUI that allows malware analysts to search through terabytes of malware using blazingly fast Yara queries. It leverages UrsaDB to accelerate queries with ngrams, providing a quick and efficient way to look through your digital warehouse. To get started, install and start using docker-compose, add files to the SAMPLES_DIR, and index your collection with ursacli in docker.
Common questions about Mquery including features, pricing, alternatives, and user reviews.
Mquery is Blazingly fast Yara queries for malware analysts with an analyst-friendly web GUI. It is a Security Operations solution designed to help security teams with YARA.
Mquery is a free Security Operations tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/CERT-Polska/mquery/ for download and installation instructions.
Popular alternatives to Mquery include:
Compare these tools and more at https://cybersectools.com/categories/security-operations
Mquery is for security teams and organizations that need YARA. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Security Operations tools can be found at https://cybersectools.com/categories/security-operations
Managed Agentic Threat Hunting Service (IOC sweeps and hypothesis based hunting)
Expands a single malware hash into full family visibility via structural analysis.