Sophos AI YaraML Rules Repository Logo

Sophos AI YaraML Rules Repository

0
Free
Visit Website

YaraML is a tool that automatically generates Yara rules from training data by translating scikit-learn logistic regression and random forest binary classifiers into the Yara language. Give YaraML a directory of malware files and a directory of benign files of any format and it'll extract substring features, downselect your feature space, train a model, and then "compile" the model and return it as a textual Yara rule. To get a feel for what this looks like, see the logistic regression Powershell detector generated by YaraML and given below.

FEATURES

ALTERNATIVES

A PowerShell module for interacting with VirusTotal to analyze suspicious files and URLs.

A curated list of open-source projects containing protestware sourced from various platforms.

ILSpy is the open-source .NET assembly browser and decompiler with various decompiler frontends and features.

Kaitai Struct is a declarative language for describing binary data structures.

Cybersecurity tool merging DarunGrim's analysis algorithms, currently in internal testing for official release.

A tool designed to handle archive file data and augment Yara's capabilities.

Tools for working with Android .dex and Java .class files, including dex-reader/writer, d2j-dex2jar, and smali/baksmali.

PLASMA is an interactive disassembler with support for various architectures and formats, offering a Python API for scripting.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved