
fibratus
Security sensor for realtime threat detection and protection

Security sensor for realtime threat detection and protection

Repository of Yara Rules

IoCs and YARA rules from Threatray's Threat Research

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Django application that performs SAST and Malware Analysis for Android APKs

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…

YARA rule analyzer to improve rule quality and performance

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Rules shared by the community from 100 Days of YARA 2026

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability…

Rules shared by the community from 100 Days of YARA 2026