YaraHunter is a malware detection tool that scans container images, running Docker containers, and filesystems using YARA rulesets to identify indicators of malware and potential compromises. The tool operates across multiple deployment scenarios: - Build-and-test environments: integrates into CI/CD pipelines to scan build artifacts for malware indicators - At-rest scanning: examines local container images before deployment to verify they are free from malware - Runtime scanning: monitors running Docker containers when unusual network traffic or CPU activity is detected - Filesystem scanning: performs on-demand scans of local filesystems for indicators of compromise Key technical capabilities include scanning both running and static containers, filesystem analysis, and CI/CD integration support. The tool is packaged as a portable Docker container and provides JSON output for automated processing and integration with other security tools. YaraHunter is designed for integration into the ThreatMapper threat discovery platform and supports automated deployment scenarios through its standardized output format.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Joe Sandbox Community provides automated cloud-based malware analysis across multiple OS platforms.
A binary analysis and management framework for organizing and analyzing malware and exploit samples, and creating plugins.
An open source .NET deobfuscator and unpacker that restores packed and obfuscated assemblies by reversing various obfuscation techniques.
A tool that extracts and deobfuscates strings from malware binaries using advanced static analysis techniques.
Intezer is a cloud-based malware analysis platform that detects and classifies malware using genetic code analysis.
A sandbox for quickly sandboxing known or unknown families of Android Malware
yextend extends Yara's functionality by automatically handling archived and compressed content inflation, enabling pattern matching on files buried within multiple layers of archives.
A .NET assembly debugger and editor that enables reverse engineering and dynamic analysis of compiled .NET applications without source code access.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.