#yara — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #yara, aggregated by home.social.
-
From now on all #CVe #CVEAlert additional to #yara #Sigma and #Suricate rules will have #Splunk #Wazuh rules all for FREE no tracking no registration, no payments! #cybersecurity #devsecops #devops #infosec #redteam #blueteam #github #gitlab #git #developers #developer info source and follow for more updates as there will be more EX: https://www.valtersit.com/cve/CVE-2026-9734/
-
Linux Incident Response: системный подход. Часть 2
Это вторая часть статьи про Linux Incident Response — разбор live response на работающем Linux-хосте с подозрением на компрометацию. Если вы не читали первую часть, лучше начать с неё: в ней разобрали принципы расследования, изоляцию хоста, trusted toolkit, фиксацию исходного состояния, сетевые соединения и процессы. Без этого контекста часть команд и логика дальнейшего анализа будут менее понятны. Первая часть здесь . В этой части процесс идет далее — к менее изменчивым артефактам. Рассмотрим механизмы закрепления и следы на диске: systemd-сервисы и timers, cron, автозапуск, пользователи, группы, пакеты, логи, kernel-артефакты. В финале расскажем о построении таймлайна, оформлении IOC и действия с системой после завершения расследования.
-
Linux Incident Response: системный подход. Часть 1
Пару лет назад я уже публиковал статью о реагировании на инциденты в Linux-системах. Она по-прежнему может быть полезна как практическая шпаргалка, но с тех пор изменился и мой опыт, и требования к таким материалам. В этом цикле статей я хочу разобрать Linux live response более системно. Большинство материалов по Linux IR сводятся к спискам команд: посмотреть процессы, сеть, пользователей, cron, логи. Проблема в том, что сами по себе команды мало что дают, если нет порядка их применения, ограничения live response, смысл полученного вывода и вообще — методологии, базиса работы. Этот материал исправляет такие упущения. Он будет разбит на две части. В этой статье обсудим принципы расследования, изоляции, подготовки инструментария, начала анализа и исследования сети и процессов. Добро пожаловать под кат.
-
THE OPEN-SOURCE ANTIVIRUS POWERED BY COMMUNITY SECURITY 🛡️
#ClamAV #OpenSource #CyberSecurity #Antivirus #Malware #YARA #ThreatDetection #InformationSecurity #Linux #Windows #macOS #EthicalHacking #TechTools #TechNews #ArtestoMellivoura
-
THE OPEN-SOURCE ANTIVIRUS POWERED BY COMMUNITY SECURITY 🛡️
#ClamAV #OpenSource #CyberSecurity #Antivirus #Malware #YARA #ThreatDetection #InformationSecurity #Linux #Windows #macOS #EthicalHacking #TechTools #TechNews #ArtestoMellivoura
-
New YARA rule targets malicious Office macros in OLE2 docs (.doc, .xls). Uses OLE2 module to scan 'Macros' stream for VBA signatures like AutoOpen/AutoExec. Works on YARA 4.0+ across Linux, Windows, macOS. #yara #snippet #ValtersIT
https://www.valtersit.com/vault/yara-rule-for-office-macro-ole2-stream-analysis-12e20d/
-
New YARA rule to detect suspicious base64 decoding in shell scripts. Matches patterns like echo [base64] | base64 -d and openssl enc -base64 -d, capturing inline and variable assignments with nocase flexibility. #yara #shell #base64 #ValtersIT
https://www.valtersit.com/vault/flag-suspicious-base64-decoding-in-shell-scripts-3ff079/
-
Schnellkochtopf
Kochen ist intuitiv, ich kann improvisieren, spontan eingreifen und das Ergebnis bleibt immer ein bisschen unvorhersehbar. Beim Backen muss man... mehr
https://radiocorax.de/schnellkochtopf/
#Dramatist #fluppe #MyUglyClementine #Schraegfunk #Schrägfunk #SnakeEyes #Yara
-
Schnellkochtopf
Kochen ist intuitiv, ich kann improvisieren, spontan eingreifen und das Ergebnis bleibt immer ein bisschen unvorhersehbar. Beim Backen muss man... mehr
https://radiocorax.de/schnellkochtopf/
#Dramatist #fluppe #MyUglyClementine #Schraegfunk #Schrägfunk #SnakeEyes #Yara
-
🚀 SO-CRATES 1.1 is here — now with Light Mode! ☀️
The tool you loved as OhMyPCAP keeps getting better.
Your all-in-one Docker/Podman container for rapid analysis of PCAPs, logs, and binaries just leveled up.
✅ PCAPs → Suricata alerts, rich metadata, ASCII transcripts, stream carving
✅ Logs → Sigma alerts + originals
✅ Binaries → YARA matches + metadataPerfect for air-gapped environments, malware analysis, IR, threat hunting, forensics & teaching.
What’s your preference?
→ Dark Mode 🖤
→ Light Mode ☀️
→ Why not both?
→ Needs glorious 4-color CGA option lol
Comment below!#DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma #DarkMode #LightMode
-
Also, notable mention. unexpected thread: https://github.com/lenucksi/aur-malware-check/issues/5
Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
Update: Looping in @archlinux here.
Also, any plans on enforcing this -> https://wiki.archlinux.org/title/DeveloperWiki:Building_in_a_clean_chroot for all the AUR build business?Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣
Edit: https://jguer.space/blog/2026-06-15-yay-v13 delivered. It's the #AURpocalypse 😱 🤣
#llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse
-
🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!
SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP.
Here's what you can do with SO-CRATES:
✅analyze pcap files and then review Suricata alerts, metadata, and extracted files
✅import log files and then review Sigma alerts and the original log entries
✅import binary files and then review YARA matches and file metadataAll of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching.
Who’s trying it out? Drop a ❤️ and reply with your main use case!
#DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma
-
🚀Introducing SO-CRATES 1.0 — Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!
SO-CRATES is a single container image for analyzing pcap files, log files, and binary files. It was formerly known as OhMyPCAP.
Here's what you can do with SO-CRATES:
✅analyze pcap files and then review Suricata alerts, metadata, and extracted files
✅import log files and then review Sigma alerts and the original log entries
✅import binary files and then review YARA matches and file metadataAll of this runs in a single Docker/Podman container — perfect for air-gapped environments, malware analysis, incident response, threat hunting, forensics & teaching.
Who’s trying it out? Drop a ❤️ and reply with your main use case!
#DFIR #Cybersecurity #BlueTeam #ThreatHunting #Suricata #YARA #Sigma
-
Мониторинг, IDS и системный анализ. YARA
YARA — инструмент для идентификации и классификации вредоносного программного обеспечения по правилам. Правила YARA описывают паттерны (строки, бинарные последовательности, регулярные выражения) в файлах. Широко используется в антивирусах, IDS, threat hunting для поиска малвари.
https://habr.com/ru/articles/1044952/
#безопастность #защита #системный_администратор #yara #ids #системный_анализ
-
🚀 OhMyPCAP 4.0.0 is HERE!
The ultimate FOSS PCAP analyzer just got a massive upgrade for deeper file intelligence.
New in v4.0:
• Upgraded to YARA Forge Full ruleset — more comprehensive malware & threat detection
• Exiftool + rich file metadata analysis — get more file information even if there are no YARA matchesAll the power you love is still here:
Suricata alerts, file alerts, Sankey diagrams, full-text search, ASCII transcripts, hexdumps, stream carving + single Docker/Podman container (perfect for air-gapped or quick spins).Ideal for malware analysis, incident response, threat hunting, forensics & teaching.
Who’s pulling this version right now? Drop a ❤️+ reply with your main use case (malware samples? CTFs? real-world incidents? teaching?)
#PCAP #DFIR #Cybersecurity #Infosec #BlueTeam #ThreatHunting #Suricata #YARA #MalwareAnalysis
-
Cuba e Vietnã ampliam cooperação agrícola com novo projeto de cultivo de arroz em Granma
-
Cuba e Vietnã ampliam cooperação agrícola com novo projeto de cultivo de arroz em Granma
-
#YARA #SHAHIDI allgraph.ro/advanced-sea... #SEABED #WARFARE www.perplexity.ai/search/new?q... semantic-map-engine.aepiot.com/semantic-map... aePiot: Empowering the present for Web 4.0. Construct nodes and own the SEO of tomorrow.
MultiSearch Tag Explorer -
RE: https://infosec.exchange/@binaryninja/116403309269355624
For the few people using #BinYars, it has been updated to support #BinaryNinja 5.3 and now targets YARA-X 1.15.0
Update via Binja's plugin manager to get the latest.
-
RE: https://infosec.exchange/@binaryninja/116403309269355624
For the few people using #BinYars, it has been updated to support #BinaryNinja 5.3 and now targets YARA-X 1.15.0
Update via Binja's plugin manager to get the latest.
-
Охота на Emmenhtal: как мы восстановили полную kill chain банковского трояна с переформатированного диска
Разбираем реальный IR-кейс: ClickFix → Emmenhtal Loader → банковский троян с Telegram C2. Форензик переформатированного диска на 930 ГБ, VDM-дисамбигуация ложноположительных и восстановление артефактов из hibernation-файла.
https://habr.com/ru/articles/1021698/
#DFIR #форензика #malware_analysis #банковский_троян #Emmenhtal #ClickFix #threat_hunting #YARA #fileless_malware #incident_response
-
ClearWater — обзор нового шифровальщика
Приветствую, сегодня я расскажу про новый шифровальщик, который мне удалось обнаружить на просторах Интернета. Первые упоминания ClearWater появились ещё в январе 2026 года. Исследуя всемирную паутину, я ещё не находил ни одной нормальной статьи по этому вредоносу, поэтому решил сам написать такую. Данный шифровальщик не отличается какой-то технической сложностью или необычными приемами поэтому его обзор несёт больше информативный характер и предназначен для Malware и TI-аналитиков.
https://habr.com/ru/articles/1018822/
#ClearWater #шифровальщик #вредонос #вредоносное_по #реверсинжиниринг #реверс #анализ_вредоносов #yara #mitre
-
Een samenvoeging van verschillende video’s die ik heb geüpload op mijn Youtube Kanaal Peter Stuif #Gezelligheid #Slechtziend #Yara Stuif
-
Yara-X 1.13 released!
Run (to get the latest): cargo install-update -i yara-x-cli
-
Yara-X 1.13 released!
Run (to get the latest): cargo install-update -i yara-x-cli
-
Yara-X has a language server for VS-Code
https://marketplace.visualstudio.com/items?itemName=VirusTotal.yara-x-ls
-
Yara-X has a language server for VS-Code
https://marketplace.visualstudio.com/items?itemName=VirusTotal.yara-x-ls
-
Released v1.3.3. of #Yaralyzer, my surprisingly popular tool for visualizing YARA rule matches with colors (a lot of colors).
1. --export-png images lets you export images of the analysis
2. almost all command line options (including multi argument ones like --yara-rules-dir) can be permanently set via environment variables or .yaralyzer file
3. couple of small bug fixes and debugging related command line options
You can try it on the web here: https://yaratoolkit.securitybreak.io/
(I didn't build this website, Thomas Roccia from Microsoft just integrated Yaralyzer into his existing site)- Github: https://github.com/michelcrypt4d4mus/yaralyzer
- Pypi: https://pypi.org/project/yaralyzer/
- on macOS you can also get it with #Homebrew by installing Pdfalyzer: brew install pdfalyzer#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #GPL #hacking #infosec #KaliLinux #maldoc #malware #malwareAnalysis #malwareDetection #openSource #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #YARA #YARArule #YARArules
-
Released v1.3.3. of #Yaralyzer, my surprisingly popular tool for visualizing YARA rule matches with colors (a lot of colors).
1. --export-png images lets you export images of the analysis
2. almost all command line options (including multi argument ones like --yara-rules-dir) can be permanently set via environment variables or .yaralyzer file
3. couple of small bug fixes and debugging related command line options
You can try it on the web here: https://yaratoolkit.securitybreak.io/
(I didn't build this website, Thomas Roccia from Microsoft just integrated Yaralyzer into his existing site)- Github: https://github.com/michelcrypt4d4mus/yaralyzer
- Pypi: https://pypi.org/project/yaralyzer/
- on macOS you can also get it with #Homebrew by installing Pdfalyzer: brew install pdfalyzer#ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #GPL #hacking #infosec #KaliLinux #maldoc #malware #malwareAnalysis #malwareDetection #openSource #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #YARA #YARArule #YARArules
-
🛠️ Tool
===================Opening:
Loki-RS is a Rust-based rewrite of the original Loki scanner that consolidates YARA rule matching and IOC detection into a single high-performance, multi-threaded binary. The project is published as Beta and emphasizes speed, concurrency, and multiple output formats for forensic ingestion.Key Features:
• YARA scanning of files and process memory with the Core YARA Forge rule set as the default detection surface.
• IOC matching covering cryptographic hashes (MD5, SHA1, SHA256), filename patterns and C2 indicators drawn from the signature-base collection.
• Concurrency model permitting configurable thread counts for parallel scanning and CPU-bound tuning.
• Archive handling with ZIP inspection to reach nested artifacts.
• Operational tooling including an interactive TUI for real-time stats and controls, HTML report generation, and JSONL output for SIEM/log pipeline ingestion.
• Remote logging via syslog over UDP/TCP, with both SYSLOG and JSON formats supported.Technical Implementation:
• The codebase leverages Rust for memory safety and performance; multi-threaded scanning suggests internal worker queues and file/process enumeration that avoid scanning virtual filesystems by default (/proc, /sys).
• Signature management integrates signature-base for IOCs and YARA Forge for rule sets; the Core rule set is chosen for accuracy and low false positives, while Extended/Full sets are available for swap-in.
• Output pathways include structured JSONL for ingestion pipelines and HTML for human-readable reporting; remote sinks support syslog framing in both traditional SYSLOG and JSON payload modes.Use Cases:
• Forensic triage on endpoints and mounts where quick identification of known artifacts (hashes, filenames, C2 indicators) is needed.
• Bulk filesystem scans across images or mounted volumes with multi-threaded throughput requirements.
• Integration with logging/monitoring stacks via JSONL or syslog exports.Limitations & Considerations:
• Project is Beta: features and signatures remain under active development.
• Signature freshness depends on external sources; operational users should plan for regular signature updates.
• Default smart filtering skips virtual filesystems and mounted drives; scanning network/cloud mounts requires explicit configuration.References:
• Detection content: signature-base (IOCs) and YARA Forge (YARA rules).🔹 tool #rust #yara #ioctools #forensics
🔗 Source: https://github.com/Neo23x0/Loki-RS
-
🛠️ Tool
===================Opening:
Loki-RS is a Rust-based rewrite of the original Loki scanner that consolidates YARA rule matching and IOC detection into a single high-performance, multi-threaded binary. The project is published as Beta and emphasizes speed, concurrency, and multiple output formats for forensic ingestion.Key Features:
• YARA scanning of files and process memory with the Core YARA Forge rule set as the default detection surface.
• IOC matching covering cryptographic hashes (MD5, SHA1, SHA256), filename patterns and C2 indicators drawn from the signature-base collection.
• Concurrency model permitting configurable thread counts for parallel scanning and CPU-bound tuning.
• Archive handling with ZIP inspection to reach nested artifacts.
• Operational tooling including an interactive TUI for real-time stats and controls, HTML report generation, and JSONL output for SIEM/log pipeline ingestion.
• Remote logging via syslog over UDP/TCP, with both SYSLOG and JSON formats supported.Technical Implementation:
• The codebase leverages Rust for memory safety and performance; multi-threaded scanning suggests internal worker queues and file/process enumeration that avoid scanning virtual filesystems by default (/proc, /sys).
• Signature management integrates signature-base for IOCs and YARA Forge for rule sets; the Core rule set is chosen for accuracy and low false positives, while Extended/Full sets are available for swap-in.
• Output pathways include structured JSONL for ingestion pipelines and HTML for human-readable reporting; remote sinks support syslog framing in both traditional SYSLOG and JSON payload modes.Use Cases:
• Forensic triage on endpoints and mounts where quick identification of known artifacts (hashes, filenames, C2 indicators) is needed.
• Bulk filesystem scans across images or mounted volumes with multi-threaded throughput requirements.
• Integration with logging/monitoring stacks via JSONL or syslog exports.Limitations & Considerations:
• Project is Beta: features and signatures remain under active development.
• Signature freshness depends on external sources; operational users should plan for regular signature updates.
• Default smart filtering skips virtual filesystems and mounted drives; scanning network/cloud mounts requires explicit configuration.References:
• Detection content: signature-base (IOCs) and YARA Forge (YARA rules).🔹 tool #rust #yara #ioctools #forensics
🔗 Source: https://github.com/Neo23x0/Loki-RS
-
https://github.com/VirusTotal/yara-x/releases/tag/v1.11.0
Time to update: cargo install-update -i yara-x-cli
-
https://github.com/VirusTotal/yara-x/releases/tag/v1.11.0
Time to update: cargo install-update -i yara-x-cli
-
This company will capture 800 000 ton CO₂ yearly and store it below the seabed.
It's not removing anything from the air as I understand it, just reducing emissions, but it's still a large positive impact.
-
This company will capture 800 000 ton CO₂ yearly and store it below the seabed.
It's not removing anything from the air as I understand it, just reducing emissions, but it's still a large positive impact.
-
Open #KLara is a community-driven fork of the original KLara project by #Kaspersky Lab, aimed at helping Threat Intelligence researchers hunt for new #malware using #Yara.
https://github.com/xdanx/open-klara -
Open #KLara is a community-driven fork of the original KLara project by #Kaspersky Lab, aimed at helping Threat Intelligence researchers hunt for new #malware using #Yara.
https://github.com/xdanx/open-klara -
#BinYars (write #YARA-X rules inside of #BinaryNinja) is now available in Binja's plugin manager!
I want to give a special shout out to @cxiao (Thank You 🙏) who provided valuable feedback making the plugin experience better.
Happy rule writing!
Learn more @ https://github.com/xorhex/BinYars
-
#BinYars (write #YARA-X rules inside of #BinaryNinja) is now available in Binja's plugin manager!
I want to give a special shout out to @cxiao (Thank You 🙏) who provided valuable feedback making the plugin experience better.
Happy rule writing!
Learn more @ https://github.com/xorhex/BinYars
-
JPCERT/CC、新しいリアルタイム脅威検出ツール「YAMAGoya」をリリース/「Sigma」「YARA」ルールをサポート、エンドポイントセキュリティを補完
https://forest.watch.impress.co.jp/docs/news/2064198.html#forest_watch_impress #YAMAGoya #Sigma #YARA #セキュリティ #Windows
-
Gen Digital disclosure: Kimsuky deployed HttpTroy via a spear-phish ZIP (250908_A_HK이노션_SecuwaySSL VPN Manager U100S 100user_견적서.zip). Chain: dropper → MemLoad (sets scheduled task AhnlabUpdate) → HttpTroy (C2 load.auraria[.]org). Notable tech: custom API hashing, XOR/SIMD string obfuscation, dynamic API resolution, in-memory DLL execution. Capabilities include file transfer, screenshot capture, command execution, process termination, and trace cleanup.
Suggested detection priorities:
• Alert on new scheduled tasks with vendor-style names (AhnlabUpdate) and correlate to recent mail attachments.
• Monitor processes performing in-memory DLL loads or unusual CreateProcessW patterns following SCR/ZIP executions.
• Block or sandbox SCR files and scrutinize embedded decoy PDFs.Share your detection rules or SIGMA/YARA ideas in the comments — and follow @technadu for source-based threat intel.
#ThreatIntel #MalwareAnalysis #HttpTroy #Kimsuky #MemLoad #EDR #Sigma #YARA #IncidentResponse #Infosec
-
Still testing 🤞
For those able to use #BinaryNinja projects; #BinYars can sort the files into folders based upon the #Yara-X rule metadata field, BNFolder. The folder nesting structure is determined by the number of matches that reside under each folder - check out the video below!
-
Still testing 🤞
For those able to use #BinaryNinja projects; #BinYars can sort the files into folders based upon the #Yara-X rule metadata field, BNFolder. The folder nesting structure is determined by the number of matches that reside under each folder - check out the video below!
-
Technical alert for SOCs & DFIR teams: RedTiger is a Python‑based infostealer now weaponized in the wild. Key behaviors: PyInstaller binaries, Discord client JS modification (discord_desktop_core index.js), token validation via /users/@me, archive upload to GoFile, webhook delivery via Discord, webcam/screenshot capture, and process/file spamming to obscure forensic traces.
Recommended triage actions:
- Hunt for modifications to discord_desktop_core or unexpected JS files.
- Monitor outbound uploads to GoFile and similar anonymous storage services.
- Alert on unusual Discord webhook creations or metadata and token validation calls to /users/@me.
- Detect mass process spawning or spamming file creation events.
- Enforce secure token storage, hardware MFA, and ephemeral credentials for services.Discuss your detection queries and signatures — share YARA, Sigma, or hunting queries in comments (safely redacted). Follow our handles for continuous threat updates.
#RedTiger #DFIR #SOC #Hunting #Sigma #YARA #ThreatIntel #Discord #Infostealer #InfoSec #Malware
-
It's getting close to being done - #BinYars a #YARA-X #BinaryNinja plugin! Still testing, but plan on open sourcing it for all to use.
Shout out to Remco Sprooten for making this tool (also shown in the video) for quickly drafting Yara rules 💪 https://github.com/1337-42/SimpleYaraBN
Video: Part 1 of 2
-
It's getting close to being done - #BinYars a #YARA-X #BinaryNinja plugin! Still testing, but plan on open sourcing it for all to use.
Shout out to Remco Sprooten for making this tool (also shown in the video) for quickly drafting Yara rules 💪 https://github.com/1337-42/SimpleYaraBN
Video: Part 1 of 2