Yara
2026-08-12
YARA
★ 17
apihash_to_yara is a tool designed to generate YARA signatures based on Windows API hashes, facilitating malware detection and hunting through obscured imports. It allows users to extract API exports from DLLs and creates YARA rules with customizable thresholds for various hash variants, making it particularly useful against malware that utilizes API hashing techniques to evade detection. Notable features include support for custom API lists and the generation of multiple hash variants to enhance detection capabilities in malware analysis workflows.
2026-08-08
YARA
★ 13
HydraDragonAV Mobile is an advanced Android antivirus solution designed to provide comprehensive threat protection through a multi-layered security architecture. It utilizes static and dynamic analysis techniques, including YARA-X and ClamAV signatures, alongside a lightweight machine learning classifier for real-time detection of malware, ransomware, and other threats. Key features include a high-speed scanning engine, native Rust implementation for efficiency, and a Zero-Trust approach to ensure that known-good applications are exempt from false positives.
2026-08-03
YARA
★ 236
Hydra Dragon Antivirus is an open-source antivirus tool primarily designed for x86-64 Windows systems, focusing on real-time protection against automated threats while avoiding the overhead of heavy signature-based detection. The tool features a minimalistic approach by utilizing key components like Owlyshield and OpenEDR, emphasizing efficiency and instant threat response without interfering with legitimate user actions. It is currently in active development, intended for expert malware analysts, and anticipates future alignment with professional testing standards.
2026-08-03
YARA
★ 166
The ThreatHunting-Keywords-yara-rules repository provides a collection of YARA rules tailored for threat hunting sessions, enabling users to identify potential threats based on specific keywords associated with offensive and greyware tools. It features two main ruleset folders: one prioritizing broader detection coverage at the cost of performance, and another optimized for higher fidelity and efficiency, along with a Python script for cross-platform scanning capabilities. The rules are systematically organized and include specialized sets for different tool types while allowing for the identification of potential threats in various file formats.
2026-03-22
YARA
★ 2562
Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android
2026-03-22
YARA
★ 1533
A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabilities.
2026-03-22
YARA
★ 2051
All-in-One malware analysis tool.
2026-03-22
YARA
★ 900
ReversingLabs YARA Rules
2026-03-22
YARA
★ 937
Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional free threat intelligence. Slava Ukraini. Glory to Ukraine.