Valhalla Logo
currently serving 24385 YARA rules and 4657 Sigma rules
API Key

New Rules per Day

Newest YARA Rules

This table shows the newest additions to the YARA rule set

Rule
Description
Date
Ref
MAL_HelloInjector_Jul26
Detects HelloInjector, a loader that uses syscalls to inject HelloProxy backdoor
28.07.2026
MAL_HelloProxy_Backdoor_Jul26
Detects HelloProxy, a proxy and a loader that hooks NtDeviceIoControlFile/closesocket/shutdown to intercept AFD-layer socket I/O, authenticates C2 connections via SOCKS5, capable of deploying additional payloads
28.07.2026
HKTL_LegacyHive_Jul26
Detects privilege escalation attempts via Legacy Hive exploiting Windows User Profile Service hive load vulnerability.
28.07.2026
MAL_APT_Shellcode_Loader_Jul26
Detects a shellcode loader that uses a custom XOR based decryption routine to load and execute shellcode from memory, seen being used by OceanLotus APT group
27.07.2026
MAL_PeatWire_SharePoint_Backdoor_Jul26
Detects PEATWIRE SharePoint backdoor variants that abuse the SignOut page to access ASP.NET MachineKey material for authentication abuse and persistent access.
27.07.2026
EXPL_PS1_CVE_2026_50522_Jul26
Detects proof-of-concept PowerShell script exploiting CVE-2026-50522
23.07.2026
EXPL_LOG_CVE_2026_50522_Jul26
Detects traces of exploitation attempts on unpatched SharePoint versions vulnerable against CVE-2026-50522 in ULS logs (i.e. patched SharePoint versions show different log lines). A match does not indicate successful exploitation. Further investigation recommended.
22.07.2026
VULN_WordPress_CVE_2026_63030_Jul26
Detects scripts vulnerable to CVE-2026-63030: Unsafe handling of author__not_in in WordPress core (class-wp-query.php)
21.07.2026
SUSP_BTminer_Lib_Jul26
Detects usage of lib btminer in binaries, a cryptocurrency miner
21.07.2026
SUSP_Ruby_Host_Recon_Jul26
Detects host reconnaissance in Ruby source files
20.07.2026
MAL_Ruby_SleeperGem_Jul26
Detects SleeperGem credential stealer written in Ruby
20.07.2026
SUSP_SH_SUID_Backdoor_Jul26
Detects shell script creating SUID backdoor
20.07.2026
MAL_SH_SleeperGem_Jul26
Detects shell scripts which download and persist a backdoor on the system - seen being used in SleeperGem campaign
20.07.2026
MAL_Go_SSH_Backdoor_Jul26
Detects executables written in Golang which drop SSH keys from a ZIP archive
20.07.2026
HKTL_AutoScan_Credential_Harvester_Jul26
Detects AutoScan tool used to harvest tokens and keys issued by AI providers from open directories
20.07.2026
MAL_BAT_IIS_Backdoor_Installer_Jul26
Detects a Batch installer that deploys a rogue native IIS module via appcmd and enables WDigest credential caching
16.07.2026
SUSP_LNX_Leashtest_Jul26
Detects Leashtest. This binary is not malicious as-is, but its presence on a device likely indicates a compromise. It is used to test rudimentary functionality on the MIPS platform.
16.07.2026
MAL_LNX_Longleash_Jul26
Detects Longleash, a Linux backdoor capable of contacting its command and control (C2), hosting a web server, managing tunnels, and acting as both a C2 server and client.
16.07.2026
MAL_Jarleash_Jul26
Detects Jarleash, a Java backdoor giving remote access to the attacker using HTTP/FTP/SFTP/NETCAT protocols
16.07.2026
MAL_LNX_Dogleash_Jul26
Detects Dogleash, a Linux backdoor capable of executing arbitrary shellcodes
16.07.2026
MAL_Implant_Indicators_Jul26
Detects characteristics found in an unknown set of loaders and shellcodes
16.07.2026
MAL_C2_MalvexC2_Implants_Jul26
Detects MalvexC2 implants, which are often used for command and control communication in post-exploitation scenarios
16.07.2026
HKTL_LNX_Phantom_Implant_Jul26
Detects unknown implants called Phantom with the capability of hiding processes and executing fileless payloads
16.07.2026
MAL_LNX_Firmware_Implant_Jul26
Detects unknown Linux firmware implants
16.07.2026
SUSP_Keylogger_Jul26
Detects a potential keylogger that captures keystrokes
16.07.2026
MAL_Kkernel_Keylogger_Jul26
Detects a kernel-mode keylogger for Windows, seen being used by APT-C-26
16.07.2026
MAL_GoLang_Veil_Stealer_Jul26
Detects golang based Veil stealer payload.
16.07.2026
SUSP_GoLang_Credential_Stealer_Indicators_Jul26
Detects golang binaries containing typical indicators of credential stealer payloads.
16.07.2026
MAL_MacOS_Bash_Dropper_Jul26
Detects a dropper written in Bash that downloads DMGs, stages application bundles, modifies code signatures, and executes payloads.
14.07.2026
MAL_MacOS_Crash_Stealer_Jul26
Detects Crash stealer that exfiltrates browser data, cryptocurrency wallets, and sensitive application data.
14.07.2026

Successful YARA Rules in Set

This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)

Rule
Average AV Detection Rate
Sample Count
Info
VT
MAL_GuLoader_Shellcode_Oct22_3
0.0
20
SUSP_MAL_EXFIL_Stealer_Output_Characteristics_Sep22_1
0.04
180
SUSP_PY_OBFUSC_Berserker_Indicators_Dec22_1
0.21
14
SUSP_BAT_OBFUSC_Apr23_2
0.59
64
SUSP_Encrypted_ZIP_Suspicious_Contents_Jul23_1_File
0.64
11
SUSP_PUA_RustDesk_Apr23_1
0.68
22
SUSP_BAT_PS1_Combo_Jan23_2
0.71
45
SUSP_JS_OBFUSC_Feb23_2
1.04
1736
SUSP_WEvtUtil_ClearLogs_Sep22_1
1.12
43
SUSP_CryptBase_PE_Info_NOT_Cryptbase_Feb23
1.19
21
SUSP_OBFUSC_PY_Loader_Jun23_1
1.48
21
SUSP_Webshell_OBFUSC_Indicators_Aug22_1
2.07
14
SUSP_URL_Split_Jun23
2.5
18
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23
2.69
13
PUA_RuskDesk_Remote_Desktop_Jun23_1
2.78
18
SUSP_JS_Redirector_Mar23
2.81
108
SUSP_JS_Executing_Powershell_Apr23
3.14
274
SUSP_PY_Reverse_Shell_Indicators_Jan23_1
3.25
16
SUSP_OBFUSC_JS_Execute_Base64_Mar23
3.26
34
SUSP_Encoded_Registry_Key_Paths_Sep22_1
3.39
64
SUSP_PE_OK_RU_URL_Jun23
3.59
17
HKTL_Clash_Tunneling_Tool_Aug22_2
3.75
16
SUSP_PY_OBFUSC_Hyperion_Aug22_1
4.0
13
SUSP_BAT_OBFUSC_Apr23_1
4.0
16
SUSP_RANSOM_Note_Aug22
4.01
171
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23_2
4.52
67
SUSP_BAT_PS1_Contents_Jan23_1
5.11
18
SUSP_OBFUSC_PS1_FormatStrings_Dec22_1
5.33
12
SUSP_BAT_OBFUSC_Apr23_4
5.35
26
SUSP_OBFUSC_BAT_Dec22_1
5.84
31

Latest YARA Matches with Low AV Detection Rate

This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)

Rule
AVs
Hash
VT
SUSP_ShellCode_Loader_Indicators_Apr21_1
14
f1d596f0462c0d1c8758b4ec8ac543d068593046c7dd832aed471a571e2b4d0b
SUSP_Enigma_Protector
14
449259937201ba88b6dd2bf15f3c62b1c9d5db86e72fab1cf31ec8b912e896ea
SUSP_Enigma_Protector
14
0ccb79409f047711d46c8c3700cbc3dbdc6d6b54df4c2912eaa87b5ec6a11009
SUSP_Enigma_Protector
13
cfdc5fedd18ccade39dd45c3cb20663ca7d8d1fa62c87f13876f4845c1b815b6
SUSP_Enigma_Protector
13
1a0d6bbb5264061a0769a30c8dc70f0b59a2b607ca7bebc5a126ae18d28b1e8a
SUSP_B64_Atob_Aug23
1
fc41598ceb4a6905a027063d04592dc647fbd6a700349d43a0020c376f932616
SUSP_Base64_Encoded_String_FromCharCode
1
fc41598ceb4a6905a027063d04592dc647fbd6a700349d43a0020c376f932616
SUSP_OBFUSC_WIN_PS1_IEX_Indicator_Aug25
1
fc41598ceb4a6905a027063d04592dc647fbd6a700349d43a0020c376f932616
SUSP_Base64_Encoded_GetObject_Winmgmts
1
fc41598ceb4a6905a027063d04592dc647fbd6a700349d43a0020c376f932616
SUSP_Encoded_ScriptLanguage_JScript
1
fc41598ceb4a6905a027063d04592dc647fbd6a700349d43a0020c376f932616
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
7
a9f544aa9865df78aec35b43e5de7ee0821ed829177d3bcfc6531123ee9344a8
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
12
f6387e259b402fc2f2b27c2128569132a46faf3791fbbdee035320694895e185
SUSP_B64_Atob_Aug23
7
a9f544aa9865df78aec35b43e5de7ee0821ed829177d3bcfc6531123ee9344a8
SUSP_B64_Atob_Aug23
12
f6387e259b402fc2f2b27c2128569132a46faf3791fbbdee035320694895e185
SUSP_Enigma_Protector
14
c6bfe59ab5da9dd7cab13df182bb6a7d377c0a014df0241cd7737b2b994e3c32
SUSP_B64_Atob_Aug23
1
dc740b84f31578ecd3070e3509e91e67eba9031ebbb246cd47df8f34c693ed2d
SUSP_Base64_Encoded_String_FromCharCode
1
dc740b84f31578ecd3070e3509e91e67eba9031ebbb246cd47df8f34c693ed2d
SUSP_Base64_Encoded_GetObject_Winmgmts
1
dc740b84f31578ecd3070e3509e91e67eba9031ebbb246cd47df8f34c693ed2d
SUSP_Encoded_ScriptLanguage_JScript
1
dc740b84f31578ecd3070e3509e91e67eba9031ebbb246cd47df8f34c693ed2d
SUSP_Enigma_Protector
14
2845b915ff40b0715ca02b93bae2212857b8e49cd37d701cce2b494d450e17ec

YARA Rules Per Category

This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)

Tag
Count
Malware
7789
Threat Hunting (not subscribable, only in THOR scanner)
5980
APT
5079
Hacktools
4889
Webshells
2404
Exploits
746

Newest Sigma Rules

This table shows the newest additions to the Sigma rule set

Rule
Description
Date
Ref
Info
Suspicious Execution of Windows Defender Critical Binaries
Detects suspicious execution of Windows Defender Binaries either executed from an unusual location or binary trying to masquerade as a legitimate Windows Defender binary. This behavior can be indicative of an attacker trying to hide their malicious binary by masquerading as a legitimate Windows Defender binary or some exploit trying to bypass Windows Defender.
15.07.2026
AllowedProcessName Registry Value Modification
Detects modification of an `AllowedProcessName` registry value under any Windows service key. Some kernel drivers and privileged services use registry-configured process paths to determine which applications are permitted to access sensitive functionality. An attacker with registry write access may modify this value to reference an attacker-controlled executable, causing the associated component to treat the malicious process as trusted. Successful abuse could grant access to privileged operations exposed by the component, such as reading protected process memory, terminating processes, or interfering with security software.
15.07.2026
Potential Ctxmui.DLL Sideloading
Detects potential DLL sideloading of "ctxmui.dll"
12.07.2026
Renamed Solid PDF Creator.EXE Execution
Detects the execution of a renamed Solid PDF Creator binary.
12.07.2026
Scheduled Task Execution with Hardcoded IPv4 Address
Detects a process spawned by the Windows Task Scheduler whose command line contains a hardcoded IPv4 address. This may indicate the execution of a task previously created to reach out to attacker-controlled IP addresses for persistence or exfiltration.
10.07.2026
Scheduled Task Created via Remotely Hosted XML File
Detects schtasks.exe creating a new scheduled task using an XML definition file hosted on a remote UNC path (hostname or IP address). Threat actors may use this technique to load malicious task definitions from attacker-controlled or compromised file shares.
09.07.2026
SQL Server Query Output to File via OSQL.EXE
Detects SQL Server queries that output results to a file using the OSQL utility. This might indicate potential attempts to save sensitive data for exfiltration or for later analysis during post-exploitation activities. Even though this could be executed in legitimate contexts, this warrants immediate investigation.
05.07.2026
VMware Binary Masquerading
Detects execution of binaries using VMware-related filenames but are not the legitimate VMware binaries. This may indicate an attempt to masquerade malicious binaries as VMware components to evade detection.
05.07.2026
VirtualBox Binary Masquerading
Detects execution of binaries using VirtualBox-related filenames which are not the legitimate VirtualBox binaries. This may indicate an attempt to masquerade malicious binaries as VirtualBox components to evade detection.
05.07.2026
Credential Added to Public IPv4 Address via Cmdkey.EXE
Detects the addition of credentials to a public IPv4 address via cmdkey.exe. Adding credential to cmdkey allows attackers to store credentials for later use. Threat Actors may use this technique to access remote systems without being prompted for credentials and use automated scripts more effectively.
05.07.2026
Network Configuration Enumeration Via WMIC NicConfig
Detects enumeration of network interface configuration via WMIC using the "nicconfig" or "nic" aliases. Attackers commonly query NIC configuration during post-exploitation reconnaissance to discover IP addresses, MAC addresses, default gateways, and DNS servers — information used to map the network and pivot to additional targets.
01.07.2026
Environment Variable Enumeration Via WMIC
Detects enumeration of environment variables via WMIC using the Win32_Environment class. Attackers query "environment get name,variablevalue" during host reconnaissance to discover paths, usernames, and configuration values useful for lateral movement or payload staging.
01.07.2026
Startup Item Enumeration Via WMIC
Detects enumeration of startup items via WMIC using the Win32_StartupCommand class. Attackers query startup items to discover persistence mechanisms that automatically execute malicious binaries or scripts during system boot or user logon.
01.07.2026
File or Directory Enumeration Via WMIC
Detects file or directory enumeration via WMIC using the Win32_Directory or CIM_DataFile classes. Attackers use these classes to list directories or files on specific drives (e.g., "C:") during post-exploitation reconnaissance - a technique that bypasses traditional dir /ls command monitoring.
01.07.2026
User Account Password Property Manipulation Via WMIC
Detects manipulation of password-related properties on user accounts via WMIC against the Win32_UserAccount class. This covers direct password changes as well as policy modifications such as disabling password expiry or preventing password changes, all common persistence techniques to maintain access to a backdoor account.
01.07.2026
Suspicious Print Processor Driver Registry Modification
Detects modifications to Windows Print Processor Driver registry values where the configured DLL is not the default winprint.dll. This may indicate abuse of Print Processors for persistence or privilege escalation, as used by malware such as SprySOCKS.
26.06.2026
SOCKS Proxy Tunneling Invocation
Detects processes that invoke SOCKS proxy tunneling via command-line arguments. Threat actors abuse SOCKS-capable tools such as chisel, revsocks, or custom SSH tunnelers to establish covert C2 channels or bypass network controls.
23.06.2026
PowerShell Enumeration of Claude Code Chat History
Detects PowerShell scripts enumerating or reading files within the Claude Code conversation history directory. Claude Code stores conversation history as JSONL files under: %USERPROFILE%\.claude\projects\<hash>\<session>.jsonl Threat actors extract these files and apply regex matching to locate high-value secrets (cloud tokens, private keys, database passwords) before pivoting to infrastructure such as ESXi hosts via harvested SSH credentials.
11.06.2026
PowerShell One-Liner Targeting Claude Code Chat History
Detects PowerShell one-liners trying to enumerate or read files within the Claude Code conversation history directory. Claude Code stores conversation history as JSONL files under: %USERPROFILE%\.claude\projects\<hash>\<session>.jsonl Threat actors extract these files and apply regex matching to locate high-value secrets (cloud tokens, private keys, database passwords) before pivoting to infrastructure such as ESXi hosts via harvested SSH credentials.
11.06.2026
PowerShell One-Liner Credential Pattern Search
Detects PowerShell or pwsh one-liners whose command line combines a regex or string-matching primitive with common credential-related keywords. It might indicate an attempt of credential harvesting across local files, including config files, source code, chat history, etc. looking for secrets such as API keys, tokens, passwords, or SSH keys.
11.06.2026
GitHub Token Access Via GH CLI
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Malicious packages and scripts have been observed using these commands to silently exfiltrate the victim's stored GitHub authentication token.
08.06.2026
GitHub Token Access Via GH CLI - Linux
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitHub repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
GitLab Token Access Via GLAB CLI
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
NPM Package Install Executed From Suspicious Location - Linux
Detects the execution of "npm install" via node on Linux from potentially suspicious directories. It might indicate a malicious package being installed or executed from a non-standard location. Attackers might use npm packages to execute malicious code on the victim's machine, potentially leading to data exfiltration, persistence, or further compromise of the system.
08.06.2026
GitLab Token Access Via GLAB CLI - Linux
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
Node or Bun Execution from Suspicious Locations - Linux
Detects the execution of build tools such as bun and node from potentially suspicious locations on Linux systems. In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute build tools such as bun and node from locations that are not commonly used for legitimate purposes.
08.06.2026
Node or Bun Execution from Suspicious Locations
Detects the execution of build tools such as bun and node from potentially suspicious locations on Windows systems. In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute build tools such as bun and node from locations that are not commonly used for legitimate purposes.
08.06.2026
NPM Package Install Executed From Suspicious Location
Detects the execution of "npm install" via node.exe from potentially suspicious directories on Windows systems. It might indicate a malicious package being installed or executed from a non-standard location. Attacker might use npm packages to execute malicious code on the victim's machine, potentially leading to data exfiltration, persistence, or further compromise of the system.
08.06.2026
NTLM Hash Leak Via Curl NTLM Authentication
Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an attacker-controlled server, enabling offline cracking or relay attacks. When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials stored in LSASS — without requiring a plaintext password. This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
04.06.2026
Uninstall SystemComponent Registry Value Modification via CommandLine
Detects modification of the "SystemComponent" registry value in the "Uninstall" key through command line. Attackers modify this value to hide installed applications from "Programs and Features", often as part of persistence or defense evasion techniques.
04.06.2026

YARA/SIGMA Rule Count

Rule Type
Community Feed
Nextron Private Feed
Yara
1391
22994
Sigma
3591
1066

Sigma Rules Per Category (Community)

Type
Count
windows / process_creation
1351
windows / registry_set
219
windows / file_event
209
windows / ps_script
166
windows / security
160
linux / process_creation
139
windows / image_load
114
webserver
82
windows / system
74
macos / process_creation
69
aws / cloudtrail
55
proxy
54
windows / network_connection
53
linux / auditd
53
azure / activitylogs
42
windows / registry_event
40
azure / auditlogs
38
windows / ps_module
33
windows / application
32
windows / dns_query
27
windows / process_access
25
azure / signinlogs
24
opencanary / application
24
okta / okta
22
azure / riskdetection
19
windows / pipe_created
19
rpc_firewall / application
17
windows / windefend
17
gcp / gcp.audit
16
linux
16
linux / file_event
15
github / audit
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / ps_classic_start
9
windows / create_stream_hash
9
windows / appxdeployment-server
9
windows / firewall-as
8
windows / msexchange-management
8
windows / file_access
7
azure / pim
7
windows / bits-client
7
gcp / google_workspace.admin
7
zeek / smb_files
7
antivirus
7
fortigate / event
7
kubernetes / audit
6
windows / dns-client
6
jvm / application
5
zeek / dns
5
linux / network_connection
5
zeek / http
5
zeek / dce_rpc
4
m365 / audit
4
windows / taskscheduler
4
windows / sysmon
4
macos / file_event
4
windows / iis-configuration
4
linux / sshd
3
windows / registry_add
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
windows / ntlm
3
linux / syslog
2
windows / security-mitigations
2
spring / application
2
windows / dns-server
2
apache
2
onelogin / onelogin.events
2
firewall
2
fortios / sslvpnd
1
linux / guacamole
1
juniper / bgp
1
windows / applocker
1
windows / openssh
1
windows / process_tampering
1
cisco / syslog
1
linux / cron
1
huawei / bgp
1
windows / appxpackaging-om
1
windows / smbclient-connectivity
1
windows / smbserver-connectivity
1
windows / file_change
1
windows / raw_access_thread
1
nodejs / application
1
paloalto / file_event / globalprotect
1
zeek / x509
1
windows / certificateservicesclient-lifecycle-system
1
windows / shell-core
1
paloalto / appliance / globalprotect
1
windows / capi2
1
windows / file_executable_detected
1
python / application
1
linux / vsftpd
1
windows / microsoft-servicebus-client
1
windows / diagnosis-scripted
1
windows / smbclient-security
1
windows / file_rename
1
windows / sysmon_status
1
ruby_on_rails / application
1
m365 / exchange
1
zeek / rdp
1
zeek / kerberos
1
windows
1
windows / sysmon_error
1
sql / application
1
m365 / threat_detection
1
windows / driver-framework
1
windows / terminalservices-localsessionmanager
1
velocity / application
1
linux / sudo
1
cisco / duo
1
nginx
1
windows / dns-server-analytic
1
database
1
cisco / bgp
1
windows / ldap
1
windows / wmi
1
windows / ps_classic_provider_start
1
windows / printservice-admin
1
cisco / ldp
1
windows / lsa-server
1
windows / printservice-operational
1
linux / clamav
1
django / application
1
linux / auth
1
windows / appmodel-runtime
1

Sigma Rules Per Category (Nextron Private Feed)

Type
Count
windows / process_creation
530
windows / registry_set
94
windows / ps_script
89
linux / process_creation
59
windows / file_event
49
windows / image_load
48
windows / security
29
windows / wmi
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ntfs
5
windows / ps_module
5
windows / dns_query
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / create_remote_thread
4
windows / registry_delete
4
macos / process_creation
3
dns
3
windows / ps_classic_script
3
windows / application-experience
3
windows / vhd
3
windows / driver_load
3
windows / hyper-v-worker
3
windows / kernel-shimengine
2
linux / Linux kernel module / THOR
2
windows / smbclient-security
2
windows / process_access
2
windows / bits-client
2
windows / windefend
2
windows / codeintegrity-operational
2
windows / file_access
2
linux / file_event
2
windows / file_delete
2
windows / file_rename
1
linux / Unix user / THOR
1
windows / environment variable / THOR
1
windows / posh_ps
1
windows / audit-cve
1
windows / application
1
windows / amsi
1
windows / firewall-as
1
windows / registry-setinformation
1
linux / file_delete
1

Tenable Nessus

Requirement: Privileged Scan

  • YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
Tutorial: https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

YARA Scanning with Nessus

  • You can only upload a single .yar file
  • Filesystem scan has to be activated
  • You have to define the target locations
  • The Nessus plugin ID will be 91990
  • Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
Tutorial: https://de.tenable.com/blog/threat-hunting-with-yara-and-nessus

Carbon Black

Tutorial: https://github.com/carbonblack/cb-yara-connector

FireEye EX

Tutorial: https://www.fireeye.com/blog/products-and-services/2018/12/detect-and-block-email-threats-with-custom-yara-rules.html