YaraHunter Logo

YaraHunter

0
Free
Visit Website

YaraHunter scans container images, running Docker containers, and filesystems to find indicators of malware. It uses a YARA ruleset to identify resources that match known malware signatures, and may indicate that the container or filesystem has been compromised. YaraHunter can be used in the following ways: - At build-and-test: scan build artifacts in the CI/CD pipeline, reporting on possible indicators of malware - At rest: scan local container images, for example, before they are deployed, to verify they do not contain malware - At runtime: scan running docker containers, for example, if you observe unusual network traffic or CPU activity - Against filesystems: at any time, YaraHunter can scan local filesystems for indicators of compromise Key capabilities: - Scan running and at-rest containers - Scan filesystems - Scan during CI/CD build operations Run anywhere: highly-portable, docker container form factor Designed for automation: easy-to-deploy, easy-to-parse JSON output YaraHunter is a work-in-progress (check the Roadmap and issues list), and will be integrated into the ThreatMapper threat discovery platform. We welcome any contributions to help improve this tool.

FEATURES

ALTERNATIVES

A collection of Android Fakebank and Tizi samples for analyzing spyware on Android devices.

A tool for deep analysis of malicious files using ClamAV and YARA rules, with features like scoring suspect files, building visual tree graphs, and extracting specific patterns.

A comprehensive guide to malware analysis and reverse engineering, covering topics such as lab setup, debugging, and anti-debugging.

Debugger and .NET assembly editor with advanced debugging features.

A fast and simple DOM based XSS vulnerability scanner

dynStruct is a tool for monitoring memory accesses of an ELF binary and recovering structures of the original code.

YARA is a tool for identifying and classifying malware samples based on textual or binary patterns.

A tool designed to handle archive file data and augment Yara's capabilities.

PINNED