YAYA is a tool that automatically curates open-source Yara rules and runs scans. It depends on external packages like go-git, go-yara, and gorm, as well as the yara4 C libraries. The tool provides commands for updating, editing, adding, scanning, and exporting Yara rules, and can also be run in a Docker container.
FEATURES
SIMILAR TOOLS
HoneyDB is a honeypot-based threat intelligence platform that provides real-time insights into attacker behavior and malicious activity on networks.
A collection of APT and cybercriminals campaigns with various resources and references.
Create deceptive webpages to deceive and redirect attackers away from real websites by cloning them.
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol, with a focus on incident handling automation and threat intelligence processing.
Maltiverse automates Threat Intelligence for small and medium-sized SecOps teams, providing an effective and affordable service.
A threat intelligence platform that collects, analyzes, and operationalizes threat data from multiple sources to help organizations identify and respond to security threats.
Cortex is a tool for analyzing observables at scale and automating threat intelligence, digital forensics, and incident response.
A tool for navigating and annotating ATT&CK matrices with the ability to define custom layers for specific views.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.