Advertisement · 728 × 90
#
Hashtag
#YARArules
Advertisement · 728 × 90
Preview
Validin introduces Support for Webhooks Validin has launched Webhooks in Beta for Enterprise users to enable real-time event ingestion for YARA rule matches and additions to threat profiles. Users can configure endpoints (including Slack) to receive HMAC SHA256-signed payloads, customize event fields, test deliveries, and build automated workflows. #Validin #YARA

Validin launches Webhooks Beta for Enterprise, enabling real-time notifications on YARA rule matches and threat profile updates. Supports Slack endpoints, HMAC SHA256 signatures, customizable fields, and delivery tests. #ThreatIntel #YARARules

0 0 0 0
Preview
How to Use YARA Retrohunting for Detection Engineering | ReversingLabs Learn how to leverage ReversingLabs’s dynamic analysis of <em>pkr_mtsi</em> for defense using YARA Rules in Spectra Analyze.

ReversingLabs' Ashlee Benge shares how to use YARA retrohunting for detection engineering by leverageing RL's dynamic analysis of "pkr_mtsi" for defense in Spectra Analyze.
👉 hubs.ly/Q043qJY-0

#yararules #detectionengineering #malwareanalysis

0 0 0 0
Preview
GitHub - c0m4r/paranoya: Simple IOC and YARA scanner for Linux® Simple IOC and YARA scanner for Linux®. Contribute to c0m4r/paranoya development by creating an account on GitHub.

Paranoya: A simple IOC and Yara scanner for Linux

Check ✅️ it out:
github.com/c0m4r/paranoya

#cybersecurity #yararules #linux

2 0 0 0
Preview
Evaluating YARA Rules for macOS Malware Hunting in Spectra Analyze | ReversingLabs With a constantly evolving OSX malware domain, it is important to write clear, specific, and accurate YARA rules. Here's how.

🔍 While macOS #malware is less widespread than Windows malware, the ability to identify, detect, & classify old & new threats alike is increasingly important. That's where #YARArules come into play: https://bit.ly/4nJKq9I

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#WeaselStore is an #infostealer used by the #APT group #DeceptiveDevelopment, which targets developers on multiple systems in web & cryptocurrency. Protect yourself by deploying our public #YARArules: https://bit.ly/3x34FdW

1 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

EggStremeFuel is a #backdoor that is part of a file-less #malware framework used by a Chinese #APT group, which recently attacked a military company in the Philippines. Don't become a victim, deploy our public #YARArules: https://bit.ly/3x34FdW

0 0 0 0
Tracking an evolving Discord-based RAT family | ReversingLabs RL's research team analyzed four RATs operated by STD Group, which yielded file indicators to better detect the malware families, plus two YARA rules.

RL's research team analyzed 4 #STDGroup-operated RATs, which yielded file indicators to better detect the #malware, plus 2 #YARArules: https://bit.ly/4npaWov

1 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

Warlock is a #ransomware based on the leaked #LockBit code, & is used by the Chinese #APT group #Storm2603 in the recent #ToolShell campaign. Protect yourself by deploying our public #YARArules: https://bit.ly/3x34FdW

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#PondRAT is a #backdoor used by the North Korean #APT group #Appleworm, & is delivered by malicious #PyPI packages in order to gain remote access to infected machines. Don't become a victim, deploy our public #YARArules: https://bit.ly/3x34FdW

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#PathWiper is a #trojan used by a Russian #APT group against Ukraine. It destroys data on physical, logical, & network drives by overwriting them with random values. Protect yourself by deploying our public #YARArules: https://bit.ly/3x34FdW #Malware #ThreatHunting

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#Pumakit is an advanced #rootkit that hides its C2 communication & system manipulation by hooking syscalls & kernel functions. Don't become a victim, deploy our public #YARArules: https://bit.ly/3x34FdW #Malware #ThreatHunting

0 0 0 0
Original post on universeodon.com

just released version 1.0.1 of The Yaralyzer. Fixes a small bug when trying to choose a byte offset to force a UTF-16 or UTF-32 decoding of matched bytes.

someone set up Yaralyzer as a #Kali package; not sure if that's made it into a release yet but if not the links are below […]

0 1 0 0
Screen cap of RecordedFuture whitepaper cover: Auto YARA: Automated Yara Rule Generation for High-confidence Threat Detection #bioinspiration

Screen cap of RecordedFuture whitepaper cover: Auto YARA: Automated Yara Rule Generation for High-confidence Threat Detection #bioinspiration

RecordedFuture's AI-driven #yararules system dynamically adjusts extraction sensitivity, enhancing precision & coverage in #malware detection. Inspired by #bioinformatics, it reduces complexity by filtering false positives based on pattern length not corpus size go.recordedfuture.com/whitepaper/a...

2 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#BackConnect is a #backdoor used by the threat actors behind #BlackBasta & #Cactus #ransomware to establish persistence on compromised systems. Don't become a victim, deploy our public #YARArules: github.com/reversinglab...

0 0 1 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#AutoColor is a #backdoor that uses advanced stealth techniques, such as hiding network activity, hooking libc functions, & preventing removal. Protect yourself by deploying our public #YARArules: github.com/reversinglab...

#Cybersecurity #ThreatHunting #Malware

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#Sshdinjector is a #backdoor which injects itself into the SSH daemon, & is used by the #Daggerfly #APT group for espionage purposes. Don't become a victim, deploy our public #YARArules: github.com/reversinglab...

#Malware #Cybersecurity

0 0 0 0
GitHub - muchdogesec/yara2stix: A command line tool that converts the YARA Rules into STIX 2.1 Objects. A command line tool that converts the YARA Rules into STIX 2.1 Objects. - muchdogesec/yara2stix

yara2stix - A command line tool that converts the YARA Rules into STIX 2.1 Objects
Check it out:
github.com/muchdogesec/...

#yararules #detectionengineering #stix #threatintelligence #threatdetection

1 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#wmRAT is another #backdoor attributed to the #APT group #TA397, & is used in attacks on organizations in the defense sector across the APAC & EMEA regions. Protect yourself by deploying our public #YARArules: bit.ly/3x34FdW

#Malware #Cybersecurity #SecOps

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#WolfsBane is a #backdoor used by the Chinese #APT group #Gelsemium to spy on organizations in Singapore, Taiwan, & the Philippines. Don't become a victim, deploy our public #YARArules: github.com/reversinglab...

#Malware #Cybersecurity #SecOps

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#Elpaco is a variant of a known #Mimic #ransomware that abuses the free file discovery library named Everything, & targets numerous countries worldwide. Protect yourself by deploying our public #YARArules: github.com/reversinglab...

#Cybersecurity #Malware

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#Elpaco is a variant of a known #Mimic #ransomware that abuses the free file discovery library named Everything, & targets numerous countries worldwide. Protect yourself by deploying our public #YARArules: github.com/reversinglab...

#Malware #Cybersecurity

0 0 0 0
Preview
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.

#MiyaRAT is a #backdoor attributed to the #APT group #TA397, which conducted multiple attacks on organizations in the defense sector across APAC & EMEA regions. Don't become a victim, deploy our public #YARArules: github.com/reversinglab...

#Cybersecurity #Malware

0 0 0 0

Quality meme by the man itself, @greg-l.bsky.social !

We are few days away from 2025! Get your YARA rules ready 👀 #100DaysOfYARA #YARARules

4 0 0 0
Preview
GitHub - RootMiner/YaraGuard: 👾 YaraGuard is a static malware analysis tool that uses YARA rules as it's core 👾 YaraGuard is a static malware analysis tool that uses YARA rules as it's core - RootMiner/YaraGuard

YaraGuard - a static malware analysis tool that uses YARA rules as it's core
Check it out 🔥🔥:
github.com/RootMiner/Ya...

#yararules #threathunting #malwareanalysis
#cybersecurity #infosec

5 3 1 0
Preview
GitHub - harryeetsource/yara_rules: community generated yara rules for detection of malware families community generated yara rules for detection of malware families - harryeetsource/yara_rules

Community Generated Yara Rules for detection of malware families
github.com/harryeetsour...

#cybersecurity #infosec #yararules #malwaredetection #threathunting #malware #infosec

10 2 0 0