Yara-Unprotect Logo

Yara-Unprotect

0
Free
Visit Website

This repository regroups the Yara Rules created for the Unprotect Project and for detecting the malware evasion techniques. Some rules are comming from https://github.com/Yara-Rules/rules/tree/master/Antidebug_AntiVM with an improvement and some modification. This repository provides a collection of Yara rules for detecting malware evasion techniques. The rules are designed to detect various evasion techniques used by malware to avoid detection. This repository is a valuable resource for security researchers and analysts to improve their malware detection capabilities. The rules are regularly updated to ensure they remain effective against the latest malware threats. This repository is a great resource for anyone working in the field of malware analysis and detection.

FEATURES

ALTERNATIVES

Explores malware interaction with Windows API and methods for detection and prevention.

An open-source binary debugger for Windows with a comprehensive plugin system for malware analysis and reverse engineering.

A tool to dump ODIN3 messages into files for reverse-engineering

A PowerShell obfuscation detection framework designed to highlight the limitations of signature-based detection and provide a scalable means of detecting known and unknown obfuscation techniques.

A Linux process injection tool that injects shellcode into a running process

ICSREF is a modular framework for automated reverse engineering of industrial control systems binaries

Interactive .NET SQL console client with enhanced SQL Server discovery, access, and data exfiltration features

A tool for reverse engineering Android apk files.