GithubHelp home page GithubHelp logo

rules's Introduction

Build Status

Project

This project covers the need of a group of IT Security Researches to have a single repository where different Yara signatures are compiled, classified and kept as up to date as possible, and begin as an open source community for collecting Yara rules. Our Yara ruleset is under the GNU-GPLv2 license and open to any user or organization, as long as you use it under this license.

Yara is being increasingly used, but knowledge about the tool and its usage is dispersed in many different places. Yara Rules project aims to be the meeting point for Yara users, gathering together a ruleset as complete as possible thus providing users a quick way to get Yara ready for usage.

We hope this project is useful for the Security Community and all Yara Users, and are looking forward to your feedback. Join this community by subscribing to our mailing list.

Contribute

If you’re interested in sharing your Yara rules with us and the Security Community, you can join our mailing list, send a message to our Twitter account or send a pull request here.

Twitter account: https://twitter.com/yararules

Mail list : http://list.yararules.com/mailman/listinfo/yararules.com.signatures

Requirements

Yara version 3.0 or higher is required for most of the rules to work. This is mainly due to the use of the "pe" module introduced in that version.

You can check your installed version with yara -v

The available packages in Ubuntu 14.04 LTS default repositories are too old. You can install from source or use the packages available in the Remnux repository.

Also, you will need Androguard Module if you want to use the rules in mobile_malware category.

Categories

Antidebug/AntiVM

In this section you will find Yara Rules aimed to detect anti debug and anti virtualization techniques used by malware to evade automated analyisis.

CVE_Rules

In this section you will find Yara Rules specialised on the identification of specifics CVE

Crypto

In this section you will find Yara rules aimed to detect the existence of cryptographic algoritms.

Exploit Kits

In this section you will find Yara rules aimed to detect the existence of Exploit Kits.

Malicious Documents

In this section you will find Yara Rules to be used with documents to find if they have been crafted to leverage malicious code.

Malware

In this section you will find Yara rules specialised on the identification of well-known malware.

Packers

In this section you will find Yara Rules aimed to detect well-known sofware packers, that can be used by malware to hide itself.

Webshells

In this section you will find Yara rules specialised on the identification of well-known webshells.

Email

In this section you will find Yara rules specialised on the identification of malicious e-mails.

Malware Mobile

In this section you will find Yara rules specialised on the indentification of well-known mobile malware.

Many rules in this section use Androguard module developed by people at https://koodous.com/.

You can get it, along with installation instructions, at https://github.com/Koodous/androguard-yara

Contact

Webpage: http://yararules.com

Twitter account: https://twitter.com/yararules

Mail list : http://list.yararules.com/mailman/listinfo/yararules.com.signatures

rules's People

Contributors

mmorenog avatar seifreed avatar jholgui avatar jovimon avatar yararules avatar xumeiquer avatar antelox avatar elhoim avatar vlad-s avatar bartblaze avatar 0pc0defr avatar xyl2k avatar garanews avatar apolkosnik-old avatar r3vrseshell avatar adamziaja avatar apolkosnik avatar diviei avatar daxda avatar felmoltor avatar merces avatar morallo avatar nodatafound avatar nyx0 avatar bobsaintcool avatar suleymanozarslan avatar taskr avatar te-k avatar niterain avatar pekeinfo avatar

Watchers

James Cloos avatar Starbuck avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.