All Projects → threat-intel → Similar Projects or Alternatives

194 Open source projects that are alternatives of or similar to threat-intel

yara-rules
Yara rules written by me, for free use.
Stars: ✭ 13 (-90%)
Mutual labels:  yara, yara-rules, threat-intelligence
nsm-attack
Mapping NSM rules to MITRE ATT&CK
Stars: ✭ 53 (-59.23%)
Threatingestor
Extract and aggregate threat intelligence.
Stars: ✭ 439 (+237.69%)
Mutual labels:  yara, threat-intelligence
yara-forensics
Set of Yara rules for finding files using magics headers
Stars: ✭ 115 (-11.54%)
Mutual labels:  yara, yara-rules
freki
🐺 Malware analysis platform
Stars: ✭ 327 (+151.54%)
Mutual labels:  yara, threat-intelligence
Analyzer
🔍 Offline Analyzer for extracting features, artifacts and IoCs from Windows, Linux, Android, iPhone, Blackberry, macOS binaries, emails and more
Stars: ✭ 108 (-16.92%)
Mutual labels:  yara, threat-intelligence
Loki
Loki - Simple IOC and Incident Response Scanner
Stars: ✭ 2,217 (+1605.38%)
Mutual labels:  yara, yara-rules
Python Iocextract
Defanged Indicator of Compromise (IOC) Extractor.
Stars: ✭ 300 (+130.77%)
Mutual labels:  yara, threat-intelligence
PhishingKit-Yara-Search
Yara scan Phishing Kit's Zip archive(s)
Stars: ✭ 24 (-81.54%)
Mutual labels:  yara, yara-rules
ThreatKB
Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)
Stars: ✭ 68 (-47.69%)
Mutual labels:  yara, yara-rules
Judge-Jury-and-Executable
A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV. Threats and data can be probed harnessing the power and syntax of SQL.
Stars: ✭ 66 (-49.23%)
Mutual labels:  yara, yara-rules
static file analysis
Analysis of file (doc, pdf, exe, ...) in deep (emmbedded file(s)) with clamscan and yara rules
Stars: ✭ 34 (-73.85%)
Mutual labels:  yara, yara-rules
yarasploit
YaraSploit is a collection of Yara rules generated from Metasploit framework shellcodes.
Stars: ✭ 31 (-76.15%)
Mutual labels:  yara, yara-rules
yara-validator
Validates yara rules and tries to repair the broken ones.
Stars: ✭ 37 (-71.54%)
Mutual labels:  yara, yara-rules
Hyara
Yara rule making tool (IDA Pro & Binary Ninja & Cutter Plugin)
Stars: ✭ 142 (+9.23%)
Mutual labels:  yara, yara-rules
Signature Base
Signature base for my scanner tools
Stars: ✭ 1,212 (+832.31%)
Mutual labels:  yara, threat-intelligence
factual-rules-generator
Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.
Stars: ✭ 62 (-52.31%)
Mutual labels:  yara, yara-rules
Freki
🐺 Malware analysis platform
Stars: ✭ 285 (+119.23%)
Mutual labels:  yara, threat-intelligence
PEiD
Yet another implementation of PEiD with yara
Stars: ✭ 12 (-90.77%)
Mutual labels:  yara, yara-rules
Ursadb
Trigram database written in C++, suited for malware indexing
Stars: ✭ 72 (-44.62%)
Mutual labels:  yara
Go Yara
Go bindings for YARA
Stars: ✭ 198 (+52.31%)
Mutual labels:  yara
Binaryalert
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
Stars: ✭ 1,125 (+765.38%)
Mutual labels:  yara
Yarasigs
Various Yara signatures (possibly to be included in a release later).
Stars: ✭ 59 (-54.62%)
Mutual labels:  yara
pyarascanner
A simple many-rules to many-files YARA scanner for incident response or malware zoos.
Stars: ✭ 23 (-82.31%)
Mutual labels:  yara
Dailyioc
IOC from articles, tweets for archives
Stars: ✭ 167 (+28.46%)
Mutual labels:  yara
Apkid
Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android
Stars: ✭ 999 (+668.46%)
Mutual labels:  yara
Masc
A Web Malware Scanner
Stars: ✭ 74 (-43.08%)
Mutual labels:  yara
Malware Indicators
Citizen Lab Malware Reports
Stars: ✭ 196 (+50.77%)
Mutual labels:  yara
Balbuzard
Balbuzard is a package of malware analysis tools in python to extract patterns of interest from suspicious files (IP addresses, domain names, known file headers, interesting strings, etc). It can also crack malware obfuscation such as XOR, ROL, etc by bruteforcing and checking for those patterns.
Stars: ✭ 70 (-46.15%)
Mutual labels:  yara
Public-Intelligence-Feeds
Standard-Format Threat Intelligence Feeds
Stars: ✭ 60 (-53.85%)
Mutual labels:  threat-intelligence
Rootkits
Stars: ✭ 63 (-51.54%)
Mutual labels:  yara
Open Source Yara Rules
YARA Rules I come across on the internet
Stars: ✭ 195 (+50%)
Mutual labels:  yara
Pecli
CLI tool to analyze PE files
Stars: ✭ 46 (-64.62%)
Mutual labels:  yara
d4-core
D4 core software (server and sample sensor client)
Stars: ✭ 40 (-69.23%)
Mutual labels:  threat-intelligence
Rpot
Real-time Packet Observation Tool
Stars: ✭ 38 (-70.77%)
Mutual labels:  yara
Binjadock
An extendable, tabbed, dockable UI widget plugin for BinaryNinja https://binary.ninja.
Stars: ✭ 34 (-73.85%)
Mutual labels:  yara
mail to misp
Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.
Stars: ✭ 61 (-53.08%)
Mutual labels:  threat-intelligence
Malware Ioc
Indicators of Compromises (IOC) of our various investigations
Stars: ✭ 955 (+634.62%)
Mutual labels:  yara
Yaraguardian
Django web interface for managing Yara rules
Stars: ✭ 156 (+20%)
Mutual labels:  yara
Operation Wocao
Operation Wocao - Indicators of Compromise
Stars: ✭ 29 (-77.69%)
Mutual labels:  yara
Iocs
IoC's, PCRE's, YARA's etc
Stars: ✭ 15 (-88.46%)
Mutual labels:  yara
Threathunting
Tools for hunting for threats.
Stars: ✭ 153 (+17.69%)
Mutual labels:  yara
Didierstevenssuite
Please no pull requests for this repository. Thanks!
Stars: ✭ 856 (+558.46%)
Mutual labels:  yara
Holmes Totem
Investigation Planner for fast running analysis with predictable execution time. For example, static analysis.
Stars: ✭ 25 (-80.77%)
Mutual labels:  yara
uzen
Website crawler with YARA detection
Stars: ✭ 84 (-35.38%)
Mutual labels:  yara
whohk
whohk,linux下一款强大的应急响应工具 在linux下的应急响应往往需要通过繁琐的命令行来查看各个点的情况,有的时候还需要做一些格式处理,这对于linux下命令不是很熟悉的人比较不友好。本工具将linux下应急响应中常用的一些操作给集合了起来,并处理成了较为友好的格式,只需要通过一个参数就能代替繁琐复杂的命令来实现对各个点的检查。
Stars: ✭ 260 (+100%)
Mutual labels:  yara
CCXDigger
The CyberCX Digger project is designed to help Australian organisations determine if they have been impacted by certain high profile cyber security incidents. Digger provides threat hunting functionality packaged in a simple-to-use tool, allowing users to detect certain attacker activities; all for free.
Stars: ✭ 45 (-65.38%)
Mutual labels:  threat-intelligence
Iocs
Sophos-originated indicators-of-compromise from published reports
Stars: ✭ 128 (-1.54%)
Mutual labels:  yara
Yargen
yarGen is a generator for YARA rules
Stars: ✭ 795 (+511.54%)
Mutual labels:  yara
Ghidra scripts
Scripts for the Ghidra software reverse engineering suite.
Stars: ✭ 732 (+463.08%)
Mutual labels:  yara
Walkoff Apps
WALKOFF-enabled applications. #nsacyber
Stars: ✭ 125 (-3.85%)
Mutual labels:  yara
Manalyze
A static analyzer for PE executables.
Stars: ✭ 701 (+439.23%)
Mutual labels:  yara
Mitigating Web Shells
Guidance for mitigation web shells. #nsacyber
Stars: ✭ 698 (+436.92%)
Mutual labels:  yara
Pepper
An open source script to perform malware static analysis on Portable Executable
Stars: ✭ 250 (+92.31%)
Mutual labels:  yara
Plyara
Parse YARA rules and operate over them more easily.
Stars: ✭ 108 (-16.92%)
Mutual labels:  yara
Die Engine
DIE engine
Stars: ✭ 648 (+398.46%)
Mutual labels:  yara
Sunburst countermeasures
Stars: ✭ 519 (+299.23%)
Mutual labels:  yara
Multiscanner
Modular file scanning/analysis framework
Stars: ✭ 494 (+280%)
Mutual labels:  yara
Yara
The pattern matching swiss knife
Stars: ✭ 5,209 (+3906.92%)
Mutual labels:  yara
Fsf
File Scanning Framework
Stars: ✭ 228 (+75.38%)
Mutual labels:  yara
1-60 of 194 similar projects