YARA is a tool aimed at helping malware researchers identify and classify malware samples.
https://virustotal.github.io/yara/
Links to this note
- defendingagainstmaliciousshims-pierce2015
- equationdeathstar-great2015
- hiddenwasp-intezer2019
- incidentresponse-luttgens2014
- tricephalichellkeeper-pourcelot2022
- unpacking diicot-tikochinski2024
- noabot-constantin2024
- evadingedr-hand2024
- yara mode
- borges2021
- sshbackdors-dumont2018
- falseflags-kaspersky2017
- Moonlight Maze YARA rules
- strings as attribution
- YARA rule
- YLS