
synacktiv-rules
Public repository of Sigma and YARA rules created by Synacktiv
forensicsintrusion-detectionioc-management+3
21

Public repository of Sigma and YARA rules created by Synacktiv

Fingerprint SSH clients and servers.

A network packet forensics tool for SSH

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Yara Rules for Modern Malware

A repository to release detection rules to the public