Skip to content
76

Awesome Yara

A curated list of awesome YARA rules, tools, and people.

4.3k stars554 forks224 entriesLast push Jun 15, 2026 (3 months ago)License Other

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

General

Victor M. Alvarez (@plusvic)

YARA

, the "pattern matching swiss knife for malware researchers (and everyone else)" is developed by @plusvic and @VirusTotal. View it on GitHub.

In 2 lists

Guides

Yara Performance Guidelines

YARA-Style-Guide

Rules

AlienVault Labs Rules

Collection of tools, signatures, and rules from the researchers at AlienVault Labs. Search the repo for .yar and .yara extensions to find about two dozen rules ranging from APT detection to generic sandbox / VM detection. Last updated in January of 2016.

anyrun rules

Public YARA rules

Apple OSX

Apple has ~40 YARA signatures for detecting malware on OSX. The file, XProtect.yara, is available locally at /System/Library/CoreServices/XProtect.bundle/Contents/Resources/.

bartblaze YARA rules

eyes:; Collection of personal YARA rules

BinaryAlert YARA Rules

A couple dozen rules written and released by AirBnB as part of their BinaryAlert tool (see next section). Detection for hack tools, malware, and ransomware across Linux, Window, and OS X. This is a new and active project.

In 3 lists

Burp YARA Rules

Collection of YARA rules intended to be used with the Burp Proxy through the Yara-Scanner extension. These rules focus mostly on non-exe malware typically delivered over HTTP including HTML, Java, Flash, Office, PDF, etc. Last updated in June of 2016.

BinSequencer

Find a common pattern of bytes within a set of samples and generate a YARA rule from the identified pattern.

CAPE Rules

eyes:; Rules from various authors bundled with the Config And Payload Extraction Cuckoo Sandbox extension (see next section).

In 3 lists

CDI Rules

Collection of YARA rules released by CyberDefenses for public use. Built from information in intelligence profiles, dossiers and file work.

Citizen Lab Malware Signatures

YARA signatures developed by Citizen Lab. Dozens of signatures covering a variety of malware families. The also inclde a syntax file for Vim. Last update was in November of 2016.

ConventionEngine Rules

sparkles:; A collection of Yara rules looking for PEs with PDB paths that have unique, unusual, or overtly malicious-looking keywords, terms, or other features.

CyStack Stealer Fingerprints

sparkles:; YARA rules and field-signature fingerprints for 30+ infostealer log families including RedLine, Vidar, Lumma and StealC. Each family folder contains a rules.yar, a sanitized sample, and fingerprint metadata (banner strings, field keys).

In 2 lists

Deadbits Rules

eyes:; A collection of YARA rules made public by Adam Swanda, Splunk's Principal Threat Intel. Analyst, from his own recent malware research.

Delivr.to Detections

This repo serves as a home for detection content developed by the delivr.to team.

Didier Stevens Rules

gem:; Collection of rules from Didier Stevens, author of a suite of tools for inspecting OLE/RTF/PDF. Didier's rules are worth scrutinizing and are generally written purposed towards hunting. New rules are frequently announced through the NVISO Labs Blog.

In 3 lists

Ditekshen Rules

A set of interrelated network and host detection rules with the aim of improving detection and hunting visibility and context.

Elastic Security YARA Rules

Elastic Security provides signature-based YARA rules within the Elastic Endpoint product. These rules are used to detect and prevent emerging threats within Linux, Windows, and macOS systems. Our repository holds over 1,000 YARA rules that are used every day to stop a wide range of threats…

In 3 lists

ESET IOCs

eyes:; Collection of YARA and Snort rules from IOCs collected by ESET researchers. There's about a dozen YARA Rules to glean from in this repo, search for file extension .yar. This repository is seemingly updated on a roughly monthly interval. New IOCs are often mentioned on the ESET…

In 4 lists

Fidelis Rules

You can find a half dozen YARA rules in Fidelis Cyber's IOC repository. They update this repository on a roughly quarterly interval. Complete blog content is also available in this repository.

Filescan.io Rules

✨; A collection of curated YARA rules used as part of the Filescan.io service.

FireEye

FireEye Red Team countermeasures detection

In 2 lists

Florian Roth Rules

eyes: :gem:; Florian Roth's signature base is a frequently updated collection of IOCs and YARA rules that cover a wide range of threats. There are dozens of rules which are actively maintained. Watch the repository to see rules evolve over time to address false positives / negatives.

In 2 lists

Florian Roth's IDDQD Rule

A proof-of-concept rule that shows how easy it actually is to detect red teamer and threat group tools and code.

f0wl yara_rules

A collection of Yara rules from

blog posts.

Frank Boldewin's Rules

A collection of YARA Rules from @r3c0nst.

FSF Rules

Mostly filetype detection rules, from the EmersonElectricCo FSF project (see next section).

In 2 lists

GoDaddy ProcFilter Rules

A couple dozen rules written and released by GoDaddy for use with ProcFilter (see next section). Example rules include detection for packers, mimikatz, and specific malware.

Google Cloud Threat Intelligence(GCTI) Rules

Rules to detect CobaltStrike framework and Sliver implant.

h3x2b Rules

gem:; Collection of signatures from h3x2b which stand out in that they are generic and can be used to assist in reverse engineering. There are YARA rules for identifying crypto routines, highly entropic sections (certificate discovery for example), discovering injection / hooking functionality,…

HydraDragonAntivirus

trophy:; World's largest open source YARA collection with no duplicates, no invalid ones and only few files. Also it contains ClamAV + YARA-X or YARA + Machine Learning + IDS canner and signatures and SUBLIME + CAPA + SIGMA signatures. Finally it has so big malware collection.

Icewater Rules

Repository of automatically generated YARA rules from Icewater.io. This repository is updated rapidly with newly generated signatures that mostly match on file size range and partial content hashes.

imp0rtp3's Rules

A small repository which contains some browser based rules.

Intezer Rules

sparkles:; YARA rules published by Intezer Labs.

In 2 lists

InQuest Rules

eyes:; YARA rules published by InQuest researchers mostly geared towards threat hunting on Virus Total. Rules are updated as new samples are collected and novel pivots are discovered. The InQuest Blog will often discuss new findings.

In 2 lists

jeFF0Falltrades Rules

sparkles:; A collection of YARA signatures for various malware families.

kevthehermit Rules

Dozens of rules from the personal collection of Kevin Breen. This repository hasn't been updated since February of 2016.

Loginsoft Rules

Yara Rules for Detecting Malicious Documents targeting Microsoft Office format.

lw-yara

Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies.

ndaal_YARA_passwords_default

YARA rules includes default credentials of at least 1043 organizations which are hashed with different hash permutations such as base64, md5, sha512, etc.

ndaal_YARA_passwords_weak

YARA rules includes hashed passwords of the top weak passwords. The passwords are hashed in a respective rule according to the following permutations such as base64, md5, sha512, etc.

NCC Group Rules

eyes:; A handful of YARA rules released by NCC Group's Cyber Defence team.

MalGamy's YARA_Rules

A small repository which contains some stealer rules.

Malice.IO YARA Plugin Rules

eyes:; Collection of topical from a variety of sources for the YARA component of the Malice.IO framework.

Malpedia Auto Generated Rules

sparkles:; A zip file that contains all automatically generated, code-based rules created using Malpedia's YARA-Signator

Malpedia Auto Generated Rules Repo

sparkles:; Repository to simplify access to and synchronization of Malpedia's automatically generated, code-based YARA rules.

McAfee Advanced Threat Research IOCs

IOCs, including YARA rules, to accompany McAfee ATR's blog and other public posts.

McAfee Advanced Threat Research Yara-Rules

Repository of YARA rules made by McAfee ATR Teams.

In 2 lists

mikesxrs YARA Rules Collection

eyes:; Large collection of open source rules aggregated from a variety of sources, including blogs and other more ephemeral sources. Over 100 categories, 1500 files, 4000 rules, and 20Mb. If you're going to pull down a single repo to play with, this is the one.

Operation Epic Fury Rules

sparkles:; YARA + Sigma detection rules for Operation Epic Fury (Iranian-linked dual-platform campaign, 2026). Covers LotAccessUI.EXE (trojanized AppEx VPN Windows RAT with RDTSC anti-VM evasion, T1497.003) and fake RedAlert Android spyware (com.red.alertx + com.net.alerts with Pushy.me C2).…

Public YARA Rules

Repository of Public YARA Rules.

QuickSand Lite Rules

This repo contains a C framework and standalone tool for malware analysis, along with several useful YARA rules developed for use with the project.

Rapid7-Labs

This repository contains a curated collection of Sigma & Yara rules and Indicators of Compromise (IOCs) shared by Rapid7 Labs.

Rastrea2r

Triage suspect systems and hunt for Indicators of Compromise (IOCs) across thousands of endpoints in minutes.

In 4 lists

ReversingLabs YARA Rules

sparkles: :eyes:; A collection of yara rules published by ReversingLabs which covers exploits, infostealers, ransomware, trojans, and viruses.

In 2 lists

Securitymagic's YARA Rules

YARA rules for a variety of threats.

Sophos AI YaraML Rules

A repository of Yara rules created automatically as translations of machine learning models. Each directory will have a rule and accompanying metadata: hashes of files used in training, and an accuracy diagram (a ROC curve).

SpiderLabs Rules

Repository of tools and scripts related to malware analysis from the researchers at SpiderLabs. There's only three YARA rules here and the last update was back in 2015, but worth exploring.

StrangeRealIntel's Daily IOCs

gem: :sparkles: :eyes:; Regularly updated YARA rules covering a variety of fresh threats.

t4d's PhishingKit-Yara-Rules

This repository, dedicated to Phishing Kits zip files YARA rules, is based on zip raw format analysis to find directories and files names, you don't need yara-extend there.

Telekom Security Malare Analysis Repository

This repository comprises scripts, signatures, and additional IOCs of our blog posts at the telekom.com blog.

Tenable Rules

Small collection from Tenable Network Security.

ThreatHunting-Keywords-yara-rules

Yara rules for Threat Hunting sessions

In 2 lists

TjadaNel Rules

Small collection of malware rules.

VectraThreatLab Rules

YARA rules for identifying anti-RE malware techniques.

Volexity - Threat-Intel

sparkles: :gem:; This repository contains IoCs related to Volexity public threat intelligence blog posts.

In 3 lists

x64dbg Signatures

gem:; Collection of interesting packer, compiler, and crypto identification signatures.

In 2 lists

YAIDS

gem: :sparkles:; YAIDS is a Multi-Threaded Intrusion Detection System using Yara. YAIDS supports all valid Yara rules (including modules) and any PCAP compatible data stream (Network, USB, Bluetooth, etc.).

YARA-FORENSICS

Collection of file type identifying rules.

YARA Forge

gem: :sparkles: :eyes:; YARA Forge specializes in delivering high-quality YARA rule packages for immediate integration into security platforms.

yara4pentesters

Rules to identify files containing juicy information like usernames, passwords etc.

YaraRules Project Official Repo

eyes:; Large collection of rules constantly updated by the community.

In 4 lists

Yara-Unprotect

Rules created for the Unprotect Project for detecting malware evasion techniques.

Unprotect Project

Detection Rule List.

Tools

AIDebug

AI-assisted malware reverse-engineering debugger that emits analyst-review YARA candidates, ATT&CK mappings, IOCs, JSON, and HTML reports.

BinaryAlert YARA Rules

A couple dozen rules written and released by AirBnB as part of their BinaryAlert tool (see next section). Detection for hack tools, malware, and ransomware across Linux, Window, and OS X. This is a new and active project.

In 3 lists

alterix

Converts Yara rules to the query language of CRYPTTECH's SIEM

androguard-yara

Androguard module for Yara.

APKiD

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

In 3 lists

a-ray-grass

YARA module that provides support for bloom filters in yara. In the context of hashlookup.io, it allows to quickly discard known files before any further analysis.

Arya- The Reverse YARA

Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA because it does exactly the opposite - it creates files that matches your rules.

Audit Node Modules With YARA Rules

Run a given set of YARA rules against the given node_module folder

AutoYara

Automated Yara Rule generation using Biclustering

base64_substring

Generate YARA rules to match terms against base64-encoded data.

bincapz

Enumerates program capabilities and malicious behaviors using fragment analysis..

CAPE Rules

eyes:; Rules from various authors bundled with the Config And Payload Extraction Cuckoo Sandbox extension (see next section).

In 3 lists

CCCS-Yara

YARA rule metadata specification and validation utility.

clara

sparkles:; Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets.

Cloudina Security Hawk

sparkles:

nullsec-yara

YARA rule development toolkit with rule generation, optimization, and testing capabilities.; Multi Cloud antivirus scanning API based on CLAMAV and YARA for AWS S3, AZURE Blob Storage, GCP Cloud Storage.

CrowdStrike Feed Management System

Framework for automating collection and processing of samples from VirusTotal, and executing commands based on YARA rule matches.

CSE-CST AssemblyLine

The Canadian Communications Security Establishment (CSE) open sourced AssemblyLine, a platform for analyzing malicious files. The component linked here provides an interface to YARA.

decompressingyara

For when your malware samples are stored compressed, but you still want to run rules against them.

dnYara

A multi-platform .NET wrapper library for the native YARA library.

ELAT

Event Log Analysis Tool that creates/uses YARA rules for Windows event log analysis.

FSF Rules

Mostly filetype detection rules, from the EmersonElectricCo FSF project (see next section).

In 2 lists

ExchangeFilter

MS Exchange transport agent uses YARA to detect malware in email messages.

factual-rules-generator

Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a running operating system.

Fadavvi YARA collection script

FARA

FARA, or Faux YARA, is a simple repository that contains a set of purposefully erroneous Yara rules. It is meant as a training vehicle for new security analysts, those that are new to Yara and even Yara veterans that want to keep their rule writing (and debugging) sharp.

Fastfinder

Fast customisable cross-platform suspicious file finder. Designed for incident response. Supports md5/sha1/sha256 hashs, litteral/wildcard strings, regular expressions and YARA rules. Can easily be packed to be deployed on any windows / linux host.

In 3 lists

findcrypt-yara

and FindYara; IDA pro plugins to scan your binary with YARA rules to find crypto constants (and more).

Fibratus

A modern tool for Windows kernel exploration and observability with a focus on security and support for YARA.

Fnord

Pattern extractor for obfuscated code.

GoDaddy ProcFilter

gem:; ProcFilter is a process filtering system for Windows with built-in YARA integration. YARA rules can be instrumented with custom meta tags that tailor its response to rule matches. It runs as a Windows service and is integrated with Microsoft's ETW API, making results viewable in the Windows…

GhidraYara

A Ghidra extension providing direct integration of YARA through an analyzer, as well as rule generation from code listings and management in the Ghidra UI. Supports an extensive library of cryptographic constants, CRC tables, etc.

go-yara

Go bindings for YARA.

In 3 lists

halogen

Halogen is a tool to automate the creation of yara rules against image files embedded within a malicious document.

Hyara

IDA Pro, Cutter, and BinaryNinja plugin that provides easy creation of YARA rules for ASCII & hex strings between a given start and end address.

In 2 lists

IDA_scripts

IDA Python scripts for generating YARA sigs from executable opcodes (.NET included).

ida_yara

Scan data within an IDB using YARA.

ida-yara-processor

IDA processor for compiled YARA rules.

InQuest ThreatKB

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL).

iocextract

Advanced Indicator of Compromise (IOC) extractor, with YARA rule extraction.

In 2 lists

Invoke-Yara

Powershell scripts to run YARA on remote machines.

java2yara

A minimal library to generate YARA rules from JAVA

KLara

Distributed system written in Python, allows researchers to scan one or more YARA rules over collections with samples.

Laika BOSS

Object scanner and intrusion detection system that strives to achieve the following goals: Scalable, Flexible, Verbose.

In 3 lists

libyara.NET

.NET wrapper for libyara built in C++ CLI used to easily incorporate yara into .NET projects

Malcat

Hexadecimal editor, disassembler and decompiler for malware analysis. Embeds both a YARA scanner and rule editor for easy in-app rule creation. Free and paid versions are available.

In 2 lists

MalConfScan

MalConfScan is a Volatility plugin extracts configuration data of known malware. This tool searches for malware in memory images and dumps configuration data. In addition, this tool has a function to list strings to which malicious code refers.

In 2 lists

malscan

Scan process memory for YARA matches and execute Python scripts if a match is found.

malwatch

Fast and lightweight malware scanner written in go that is ideal for Linux based web server environments. Currently used with some of the internet's largest deployments.

Manalyzer Yara Validator

Compile your rules on all yara versions online to detect compatibility issues!

MISP Threat Sharing

Threat intelligence platform including indicators, threat intelligence, malware samples and binaries. Includes support for sharing, generating, and validating YARA signatures.

In 3 lists

MITRE MultiScanner

File analysis framework that assists the user in evaluating a set of files by automatically running a suite of tools for the user and aggregating the output.

In 4 lists

mkYARA

Generate YARA rules based on binary code.

mquery

Web frontend for running blazingly fast YARA queries on large datasets.

ndaal YARA ruleset checker

ndaal YARA ruleset checker, Open Source

Loki

IOC and YARA rule scanner implemented in Python. Open source and free.

In 4 lists

THOR Lite

IOC and YARA rule scanner implemented in Go. Closed source, free, but registration required.

node-yara

YARA support for Node.js.

ocaml-yara

OCaml bindings to libyara

OCYara

Performs OCR on image files and scans them for matches to YARA rules.

osquery

YARA-based scanning with osquery.

PasteHunter

Scan pastebin.com with YARA rules.

plast

Threat hunting tool for detecting and processing IOCs using YARA under the hood.

plyara

Parse YARA rules with Python.

Polichombr

Collaborative malware analysis framework with YARA rule matching and other features.

In 2 lists

PwC Cyber Threat Operations rtfsig

This tool is designed to make it easy to signature potentially unique parts of RTF files.

Rustinel

Open-source endpoint detection engine for Windows and Linux that scans executables with YARA on process creation and combines results with Sigma and IOC detections.

In 2 lists

VirusTotalTools

Tools for checking samples against Virus Total, including VT_RuleMGR, for managing threat hunting YARA rules.

shotgunyara

Given a string, create 255 xor encoded versions of that string as a YARA rule.

spyre

Simple, self-contained YARA-based file IOC scanner.

In 2 lists

static_file_analysis

Analyze deeply embedded files (doc, pdf, exe, ...) with clamscan and YARA.

stoQ

Modular and highly customizable framework for the creation of data sets from multiple disparate data sources.

Strelka

Detection-Oriented File Analysis System built on Python3, ZeroMQ, and YARA, primarily used for threat detection/hunting and intelligence gathering.

Sysmon EDR

sparkles:; YARA scanning, process killing, network blocking, and more.

SwishDbgExt

Microsoft WinDbg extension which includes the ability to use YARA rules to hunt processes in memory.

In 2 lists

ThreatIngestor

Automatically extract and aggregate IOCs including YARA rules from many sources.

In 5 listsDetails

UXProtect

The missing UI to Apple's built-in XProtect YARA signatures. Enumerate signatures, scan files, and more.

VTCodeSimilarity-YaraGen

gem: :sparkles:; Yara rule generator using VirusTotal code similarity feature code-similar-to: written by @arieljt.

Vxsig

sparkles:; Automatically generate AV byte signatures from sets of similar binaries.

yabin

Creates YARA signatures from executable code within malware.

yaml2yara

Generate bulk YARA rules from YAML input.

YARA-CI

sparkles:; YARA-CI helps you to keep your YARA rules in good shape. It can be integrated into any GitHub

yaradbg-backend

gem:; YaraDbg is a free web-based Yara debugger to help security analysts to write hunting or detection rules with less effort and more confidence.

yaradbg-frontend

eyes:; YaraDbg is a free web-based Yara debugger to help security analysts to write hunting or detection rules with less effort and more confidence.

yara-endpoint

Tool useful for incident response as well as anti-malware enpoint based on YARA signatures.

YaraFileCheckerLib

.Net Library designed to make it easier to check potentially malicious files and archives using YARA and make a decision about their harmfulness based on the weights of the detected rules.

YaraGenerator

Quick, simple, and effective yara rule creation to isolate malware families and other malicious objects of interest.

YaraGen

and yara_fn; Plugins for x64dbg and IDAPython, respectively, that generate YARA rules from function blocks.

YaraGuardian

Django web interface for managing YARA rules.

YaraHunter

Malware scanner for cloud-native, as part of CI/CD and at Runtime

yara-java

Java bindings for YARA (Subreption fork, maintained as of 2024, old bindings).

yaralyzer

Visually inspect and force decode YARA and regex matches found in both binary and text data. With Colors.

yaramail

A YARA scanner designed for phishing triage automation. Categorizes emails email authentication, attachments, and normalized body content.

yaraMail

YARA scanner for IMAP feeds and saved streams.

Yara Malware Quick menu scanner

Adds the awsome YARA pattern scanner to Windows right click menus.

YaraManager

Web based manager for YARA rules.

Yaramanager

(PyPI); Command line tool to manage and organize your Yara ruleset.

yaramod

A library that provides parsing of YARA rules into AST and a C++ programming interface to build new YARA rulesets.

yarAnalyzer

YARA rule set coverage analyzer.

yara-ocaml

OCaml bindings for YARA

yara-parser

Tools for parsing rulesets using the exact grammar as YARA. Written in Go.

yaraparser

Python 3 tool to parse Yara rules.

yaraPCAP

YARA scanner For IMAP feeds and saved streams.

In 2 lists

yara-procdump-python

Python extension to wrap the YARA process memory access API.

yara-rust

Rust bindings for VirusTotal/Yara

yara-signator

sparkles:; Automatic YARA rule generation for Malpedia

YARA-sort

Aggregate files into collections basd on YARA rules. blog

Yara Python ICAP Server

ICAP server with YARA scanner.

In 2 lists

yarasafe

Automatic generation of function signature using machine learning.

Yara-Scanner

Python-based extension that integrates a YARA scanner into Burp Suite.

yarascanner

Golang-based web service to scan files with YARA rules.

YaraSharp

C# wrapper around the Yara pattern matching library

Yara Toolkit

This is the Yara editor. You can write your own Yara rules or copy paste one to edit it.

YaraStation

Yara station is a managment portal designed to facilitate the use of Loki scanner.

yara_tools

Python bindings to author YARA rules using natural Python conventions.

Yara-Validator

Validates YARA rules and tries to repair the broken ones.

yaraVT

Scan files with Yara and send rule matches to VirusTotal reports as comments.

yara_zip_module

Search for strings inside a zip file.

yarg

IDAPython plugin for gerenating YARA rules from x86/x86-64 code.

yarGen

YARA rule generator for finding related samples and hunting.

In 4 lists

Yara Scanner

A wrapper around the yara-python project the providing multiple capabilities.

Yarasilly2

A Semi automatic handy tool to generate YARA rules from sample virus files ( WIP ) for Malware Analyst, inspired by DIFF function of VirusTotal Premium Account.

yaya

Automatically curate open source yara rules and run scans.

YaYaGen

YARA rule generator for Android malware.

Yeti

Platform meant to organize observables, indicators of compromise, TTPs, and knowledge on threats in a single, unified repository.

In 3 lists

yextend

YARA integrated software to handle archive file data.

yaraZeekAlert

sparkles:; Scans files with YARA rules and send email alerts which include network context of the file transfer and attaches the suspicious file if it is less than 10 MB.

yaraScanParser

Parsing tool for Yara Scan Service's JSON output file.

YARI

Interactive debugger for the YARA language written in Rust.

YLS

Language server for YARA to intergrate with e.g. vscode or vim. Offers code completion, function documentation, code formatting, debugging, ...

YMCA

Displays a table of matches between YARA rules and a collection of samples.

Yobi

sparkles:; Yobi is a basic firefox extension which allows to run public or private YARA rules on all scripts and pages rendered by the browser.

statiStrings

Strings statistics calculator for YARA rules.

Services

Hybrid Analysis YARA Search

YARA search / hunting from CrowdStrike / Hybrid Analysis, powered by Falcon MalQuery.

InQuest Labs

sparkles: :gem:; See the YARA section for helper routines to convert regular expressions to match on base64 encoded strings, conver strings to sequences of uint() lookups, and more.

In 3 lists

Koodous

Collaborative platform for APK analysis, with community YARA rule repository and large APK sample dataset.

In 2 lists

MalShare

Free malware repository providing researchers access to samples, malicous feeds, and YARA results.

In 4 listsDetails

MalwareConfig

Extract IOCs from Remote Access Trojans.

In 2 lists

YaraEditor (Web)

All-in-one website to create and manage YARA rules.

YARAify

sparkles:; YARAify is a project from abuse.ch that allows anyone to scan suspicious files such as malware samples or process dumps against a large repository of YARA rules.

In 2 lists

Yara Scan Service

A simple service to test your Yara rules against a large set of malicious and identified files.

Videos and Talks

Finding Evil with YARA

SAS2018: Finding aliens, star weapons and ponies with YARA

Costin Raiu - Combining code similarity with Yara to find goodies

YARA Rule Processing Sessions - Florian Roth

Upping the APT hunting game: learn the best YARA practices from Kaspersky

Star-Gazing | Using a Full Galaxy of YARA Methods to Pursue an Apex Actor | By Greg Lesnewich

Lightweight Binary Similarity - YARA Using PE Features for Quick Wins

DEF CON 26 - Andrea Marcelli - Looking for the perfect signature an automatic YARA rules

See category
94

Awesome OpenClaw Skills

VoltAgent/awesome-openclaw-skills

The awesome collection of OpenClaw skills. 5,400+ skills filtered and categorized from the official OpenClaw Skills Registry.🦞

Fresh★ 53k830 entriesPushed today
92

Awesome DeepSeek Harness (DSH) Plugin

awesome-dsh-plugin/awesome-dsh-plugin

A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表

Fresh★ 17k1654 entriesPushed today
91

Awesome Guidelines

Kristories/awesome-guidelines

Programming style, best practices, and coding conventions.

Fresh★ 11k166 entriesPushed 2 days ago
90

Awesome

sindresorhus/awesome

😎 Awesome lists about all kinds of interesting topics [NOTE: Pull requests are temporarily disabled until I have a chance to catch up with the existing ones]

Fresh★ 513k51 entriesPushed 28 days ago
90

Awesome Prompts

ai-boost/awesome-prompts

Curated list of chatgpt prompts from the top-rated GPTs in the GPTs Store. Prompt Engineering, prompt attack & prompt protect. Advanced Prompt Engineering papers.

Fresh★ 9k288 entriesPushed yesterday
90

Awesome README

matiassingers/awesome-readme

A curated list of awesome READMEs

Fresh★ 22k143 entriesPushed yesterday