discovered 12 Aug 2026
apihash_to_yara
→ View on GitHubapihash_to_yara is a tool designed to generate YARA signatures based on Windows API hashes, facilitating malware detection and hunting through obscured imports. It allows users to extract API exports from DLLs and creates YARA rules with customizable thresholds for various hash variants, making it particularly useful against malware that utilizes API hashing techniques to evade detection. Notable features include support for custom API lists and the generation of multiple hash variants to enhance detection capabilities in malware analysis workflows.