VT Code Similarity Yara Generator Logo

VT Code Similarity Yara Generator

0
Free
Updated 11 March 2025
Visit Website

This Yara generator utilizes VirusTotal's 'code-similar-to:' beta search modifier to extract code blocks from PE files and automatically generate a Yara signature, allowing for the hunting of similar APT samples with refined results using Kaspersky KTAE. It requires a VirusTotal Enterprise API key, Python 2/3, requests, and json. The tool accepts a PE file hash, queries VirusTotal for files sharing code blocks, and post-processes the results based on user-defined code block length and similarity score thresholds. It then collects code blocks, their offset, and filesize from each file to determine the file size range for the Yara rule, ranking the most popular code blocks for user selection.

FEATURES

SIMILAR TOOLS

Repository containing MITRE ATT&CK and CAPEC datasets in STIX 2.0 for cybersecurity threat modeling.

ZoomEye is an advanced cyberspace search engine that provides detailed information on cyberspace assets, including server software and version information, for cybersecurity experts, researchers, and enterprises.

A PowerShell module for threat hunting via Windows Event Logs

In-depth analysis of real-world attacks and threat tactics

Nessus efficiently scans for system vulnerabilities, misconfigurations, and compliance issues.

A modular malware collection and processing framework with support for various threat intelligence feeds.

Scan files or process memory for Cobalt Strike beacons and parse their configuration.

A platform providing an activity feed on exploited vulnerabilities.

Automated framework for collecting and processing samples from VirusTotal with YARA rule integration.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved