• Stars
    star
    358
  • Rank 118,083 (Top 3 %)
  • Language
    Python
  • License
    MIT License
  • Created almost 7 years ago
  • Updated over 2 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.

yara-rules

A collection of YARA rules from the folks at InQuest we wish to share with the world. These rules should not be considered production appropriate. Rather, they are valuable for research and hunting purposes.

See also:

The rules are listed here, alphabetically, along with references for further reading:

More Repositories

1

awesome-yara

A curated list of awesome YARA rules, tools, and people.
3,362
star
2

malware-samples

A collection of malware samples and relevant dissection information, most probably referenced from http://blog.inquest.net
ActionScript
873
star
3

ThreatIngestor

Extract and aggregate threat intelligence.
Python
800
star
4

iocextract

Defanged Indicator of Compromise (IOC) Extractor.
Python
495
star
5

omnibus

The OSINT Omnibus (beta release)
Python
315
star
6

sandboxapi

Minimal, consistent Python API for building integrations with malware sandboxes.
Python
132
star
7

ThreatKB

Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)
JavaScript
94
star
8

yara-rules-vt

Collection of YARA rules designed for usage through VirusTotal.com.
YARA
61
star
9

python-inquestlabs

A Pythonic interface and command line tool for interacting with the InQuest Labs API.
Python
34
star
10

microsoft-office-macro-clustering

Jupyter Notebook
16
star
11

labs-experiments

A collection of experiments overtop the InQuest Labs open data portal (https://labs.inquest.net).
Python
3
star
12

splunk-inquest

Splunk Addon for InQuest.
Python
3
star
13

iqui-icons

2
star
14

iqui-ngx

Angular CDK based, Bootstrap styled components library
TypeScript
2
star
15

python-threatkb

Python library and command-line tool for InQuest ThreatKB. (pre-release)
Python
2
star
16

iq-cli

InQuest Platform v3 CLI and Python Library
Python
1
star
17

ipython-notebooks

A collection of iPython notebooks probably referenced from https://inquest.net/blog
Jupyter Notebook
1
star
18

RFIQ-Card

Recorded Future InQuest Labs Integration
Python
1
star