awesome-yara
awesome-incident-response
Our great sponsors
awesome-yara | awesome-incident-response | |
---|---|---|
7 | 4 | |
3,245 | 7,114 | |
2.9% | - | |
5.6 | 5.6 | |
14 days ago | 25 days ago | |
GNU General Public License v3.0 or later | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
awesome-yara
- XSOAR Yara Feeds
- Incorporating YARA Into Security Processes?
-
Cybersecurity Repositories
YARA
-
YARA Rules for Malware
Check out the myriad of resources available here: https://github.com/InQuest/awesome-yara
-
Identifying packers, crypters or protectors
A signature-based approach with YARA can work to fingerprint the specific software used to obfuscate the malware. A lot of YARA rules for a variety of purposes can be found here, and it might be useful to aggregate ones you care about into your own little detection pipeline.
-
What are the best FOSS YARA rules you would recommend to deploy?
https://github.com/InQuest/awesome-yara#rules
- InQuest/awesome-yara - A curated list of awesome YARA rules, tools, and people.
awesome-incident-response
-
Cybersecurity Repositories
Incident Response
- Questions about getting into DF
-
I started a new role as a Incident Response Analyst and wanted to get some advice.
Here is a good github page that discusses tons of IR stuff. https://github.com/meirwah/awesome-incident-response
-
Has this sub done any curated reasearch collection sharing?
GitHub sounds totally viable. You might consider styling it after something like Awesome Lists. (Ex: Awesome Incident Response). But yes, totally viable.
What are some alternatives?
malware-ioc - Indicators of Compromises (IOC) of our various investigations
Kuiper - Digital Forensics Investigation Platform
signature-base - YARA signature and IOC database for my scanners and tools
cyberchef-recipes - A list of cyber-chef recipes and curated links
awesome-malware-analysis - Defund the Police.
dfir-orc - Forensics artefact collection tool for systems running Microsoft Windows
yara - The pattern matching swiss knife
DevSecOps - Ultimate DevSecOps library
audit-node-modules-with-yara - Audit Node Module folder with YARA rules to identify possible malicious packages hiding in node_moudles
DFIRMindMaps - A repository of DFIR-related Mind Maps geared towards the visual learners!
Detect-It-Easy - Program for determining types of files for Windows, Linux and MacOS.
awesome-sre - A curated list of Site Reliability and Production Engineering resources.