Repository of YARA rules to accompany the Trellix ATR blogposts & investigations. We endorse contributing to improve our rules - please send us a pull request with your proposal. In case you discovered a false positive with our rules, please share with us your details in an issue report and we’ll try to improve our Yara rules. Happy Hunting!
FEATURES
ALTERNATIVES
A tool for translating Dalvik bytecode to Java bytecode for analyzing Android applications.
A strings statistics calculator for YARA rules to aid malware research.
YaraHunter scans container images, running Docker containers, and filesystems to find indicators of malware.
A script to detect and remove Canary Tokens with simple signature-based detections.
A better version of my xssfinder tool that scans for different types of XSS on a list of URLs.
A framework for creating XNU based rootkits for OS X and iOS security research
A collection of reverse engineering challenges covering a wide range of topics and difficulty levels.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.