LogoAISecKit
  • Search
  • Collection
  • Category
  • Tag
  • Blog
  • Pricing
  • Submit
LogoAISecKit

Newsletter

Join the Community

Subscribe to our newsletter for the latest news and updates

LogoAISecKit

Curated directory of 1700+ AI tools, models, frameworks, MCP servers, and cybersecurity resources

GitHub
Product
  • Search
  • Collection
  • Category
  • Tag
Resources
  • Blog
  • Pricing
  • Submit
Company
  • About Us
  • Privacy Policy
  • Terms of Service
  • Sitemap
Copyright © 2026 All Rights Reserved.
Sponsored Resources
  1. Home
  2. Category
  3. ThreatHunting-Keywords-yara-rules
icon of ThreatHunting-Keywords-yara-rules

ThreatHunting-Keywords-yara-rules

YARA detection rules for threat hunting using the ThreatHunting-Keywords project.

Visit Website
image for ThreatHunting-Keywords-yara-rules
Visit Website

Introduction

Detailed Introduction

The ThreatHunting-Keywords-yara-rules project provides a set of YARA detection rules tailored for hunting threats using keyword patterns from the ThreatHunting-Keywords project. The aim is to facilitate threat hunting sessions and enable comprehensive large-scale triage. The rules are organized into recognized categories to enhance detection capabilities:

  1. Offensive Tool Keywords: Keywords associated with known offensive tools, designed to minimize false positives, ensuring high confidence in detecting potential threats.
  2. Greyware Tool Keywords: Keywords related to legitimate tools that can be exploited by malicious actors, where the detection may result in higher false positives.
  3. Signature Keywords: Keywords not directly tied to tools but include critical terms or names important for threat detection.

The project also includes:

  • An all-encompassing YARA file for broad detection coverage.
  • A Python script (scan.py) for cross-platform scanning of directories and files.
  • Detailed documentation and examples illustrating how to utilize these YARA rules effectively for security purposes.

By utilizing these rules, security professionals can improve their threat detection processes and refine their incident response strategies.

Back

Information

  • Publisher
    AISecKit
  • Websitegithub.com
  • Published date2025/04/28

Categories

  • Incident Response Tools
  • DevSecOps Tools

Tags

  • Incident Response
  • Threat Intelligence

More Products

image of Phantom
DevSecOps ToolsPenetration TestingVulnerability Scanners
Visit Website
icon of Phantom

Phantom

A browser extension for SRC vulnerability mining, collecting sensitive information and suspicious clues from web pages.

Security AuditingOpen SourceIncident ResponseVulnerability ScanningAPI Security+1
K
DevSecOps ToolsAI Security Monitoring
Visit Website
icon of Kereva LLM Code Scanner

Kereva LLM Code Scanner

Code scanner to check for issues in prompts and LLM calls

Code AssistantsPrompt EngineeringAI EthicsComplianceLLM+1
A
AI Application PlatformsDevSecOps ToolsContainer Security
Visit Website
icon of Ansible Web Management Panel

Ansible Web Management Panel

可视化Ansible Web管理面板,提供批量主机管理、命令执行、文件传输和Web终端等功能。

Security AuditingOpen SourceContainer SecurityDevSecOps