> cat /dev/github | grep security-tools
discovered 03 Aug 2026

capa-rules

via awesome-list
→ View on GitHub
The capa-rules repository provides a comprehensive collection of rules designed for the capa tool, which automates the detection of capabilities within executable programs. Its primary use case is to enable users to create and extend rules that assist in identifying specific actions or features in malware, promoting community-driven contributions. Notable features include a user-friendly rule-writing format that combines aspects of OpenIOC, Yara, and YAML, as well as a structured namespace organization for categorizing rules by their functional domains.