YaraML is a tool that automatically generates Yara rules from training data by translating scikit-learn logistic regression and random forest binary classifiers into the Yara language. Give YaraML a directory of malware files and a directory of benign files of any format and it'll extract substring features, downselect your feature space, train a model, and then "compile" the model and return it as a textual Yara rule. To get a feel for what this looks like, see the logistic regression Powershell detector generated by YaraML and given below.
FEATURES
ALTERNATIVES
A PowerShell module for interacting with VirusTotal to analyze suspicious files and URLs.
A curated list of open-source projects containing protestware sourced from various platforms.
ILSpy is the open-source .NET assembly browser and decompiler with various decompiler frontends and features.
Kaitai Struct is a declarative language for describing binary data structures.
Cybersecurity tool merging DarunGrim's analysis algorithms, currently in internal testing for official release.
A tool designed to handle archive file data and augment Yara's capabilities.
Tools for working with Android .dex and Java .class files, including dex-reader/writer, d2j-dex2jar, and smali/baksmali.
PLASMA is an interactive disassembler with support for various architectures and formats, offering a Python API for scripting.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.