Valhalla Logo
currently serving 24363 YARA rules and 4655 Sigma rules
API Key

New Rules per Day

Newest YARA Rules

This table shows the newest additions to the YARA rule set

Rule
Description
Date
Ref
VULN_WordPress_CVE_2026_63030_Jul26
Detects scripts vulnerable to CVE-2026-63030: Unsafe handling of author__not_in in WordPress core (class-wp-query.php)
21.07.2026
HKTL_AutoScan_Credential_Harvester_Jul26
Detects AutoScan tool used to harvest tokens and keys issued by AI providers from open directories
20.07.2026
MAL_Implant_Indicators_Jul26
Detects characteristics found in an unknown set of loaders and shellcodes
16.07.2026
MAL_C2_MalvexC2_Implants_Jul26
Detects MalvexC2 implants, which are often used for command and control communication in post-exploitation scenarios
16.07.2026
HKTL_LNX_Phantom_Implant_Jul26
Detects unknown implants called Phantom with the capability of hiding processes and executing fileless payloads
16.07.2026
MAL_LNX_Firmware_Implant_Jul26
Detects unknown Linux firmware implants
16.07.2026
MAL_GoLang_Veil_Stealer_Jul26
Detects golang based Veil stealer payload.
16.07.2026
SUSP_GoLang_Credential_Stealer_Indicators_Jul26
Detects golang binaries containing typical indicators of credential stealer payloads.
16.07.2026
SUSP_LNX_Leashtest_Jul26
Detects Leashtest. This binary is not malicious as-is, but its presence on a device likely indicates a compromise. It is used to test rudimentary functionality on the MIPS platform.
16.07.2026
MAL_LNX_Longleash_Jul26
Detects Longleash, a Linux backdoor capable of contacting its command and control (C2), hosting a web server, managing tunnels, and acting as both a C2 server and client.
16.07.2026
MAL_Jarleash_Jul26
Detects Jarleash, a Java backdoor giving remote access to the attacker using HTTP/FTP/SFTP/NETCAT protocols
16.07.2026
MAL_LNX_Dogleash_Jul26
Detects Dogleash, a Linux backdoor capable of executing arbitrary shellcodes
16.07.2026
MAL_JS_Miasma_Worm_Jul26
Detects Miasma Worm written in JavaScript and deployed via poisoned NPM packages; The worm establishes a persistent Node.js backdoor allowing additional payloads to be executed.
14.07.2026
MAL_DynLoader_Jul26
Detects Dynloader that uses PEB parsing and indirect syscalls to load and inject shellcode into local or remote processes
14.07.2026
MAL_Generic_Loader_Jul26
Detects malicious patterns of loaders that resolve functions from PEB and use syscalls to load payloads
14.07.2026
MAL_MacOS_Bash_Dropper_Jul26
Detects a dropper written in Bash that downloads DMGs, stages application bundles, modifies code signatures, and executes payloads.
14.07.2026
MAL_MacOS_Crash_Stealer_Jul26
Detects Crash stealer that exfiltrates browser data, cryptocurrency wallets, and sensitive application data.
14.07.2026
MAL_IronWorm_Jul26
Detects IronWorm credential stealer
14.07.2026
HKTL_VeeamDumper_Jul26
VeeamDumper, a credential extraction hacktool for Veeam Backup & Replication and Veeam One
13.07.2026
MAL_GigaWiper_Jul26
Detects GigaWiper and it's backdoor version
13.07.2026
MAL_USP_Backdoor_Jul26
Detects USP, a Linux backdoor using a udev rule that triggers the execution of a specified payload (binary or script)
13.07.2026
MAL_ELF_Backdoor_Jul26
Detects an ELF Linux backdoor seen in the wild in combination with the USP backdooring method
13.07.2026
MAL_BootBypass_Jul26
Detects BootBypass, a hacktool for bypassing DSE and HVCI
13.07.2026
MAL_Zohomurk_Jul26
Detects Zohomurk implant, seen being used by Mustang Panda
13.07.2026
MAL_ShardLoader_Jul26
Detects ShardLoader that decrypts and launches implants, seen being used by Mustang Panda
13.07.2026
MAL_IronWorm_CSI_Format_Jul26
Detects custom container format 'CSI' seen being used by IronWorm malware
13.07.2026
MAL_IronWorm_CSI_Parser_Jul26
Detects JavaScript parser for custom container format 'CSI' seen being used by IronWorm malware
13.07.2026
MAL_P3_Loader_Jul26
Detects p3-loader, a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote processes, without triggering common detection mechanisms.
13.07.2026
LOG_ANYDESK_Trace_Login_IP_Jul26
Detects AnyDesk trace log entries that record the client IP address of an incoming session for analyst review and correlation.
12.07.2026
SUSP_JS_Obfuscated_Script_Element_FromCharCode_Jul26
Detects JavaScript that reconstructs the string 'script' using String.fromCharCode, potentially concealing dynamic script element creation and remote payload loading
11.07.2026

Successful YARA Rules in Set

This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)

Rule
Average AV Detection Rate
Sample Count
Info
VT
MAL_GuLoader_Shellcode_Oct22_3
0.0
20
SUSP_MAL_EXFIL_Stealer_Output_Characteristics_Sep22_1
0.04
180
SUSP_PY_OBFUSC_Berserker_Indicators_Dec22_1
0.21
14
SUSP_BAT_OBFUSC_Apr23_2
0.59
64
SUSP_Encrypted_ZIP_Suspicious_Contents_Jul23_1_File
0.64
11
SUSP_PUA_RustDesk_Apr23_1
0.68
22
SUSP_BAT_PS1_Combo_Jan23_2
0.71
45
SUSP_JS_OBFUSC_Feb23_2
1.04
1736
SUSP_WEvtUtil_ClearLogs_Sep22_1
1.12
43
SUSP_CryptBase_PE_Info_NOT_Cryptbase_Feb23
1.19
21
SUSP_OBFUSC_PY_Loader_Jun23_1
1.48
21
SUSP_Webshell_OBFUSC_Indicators_Aug22_1
2.07
14
SUSP_URL_Split_Jun23
2.5
18
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23
2.69
13
PUA_RuskDesk_Remote_Desktop_Jun23_1
2.78
18
SUSP_JS_Redirector_Mar23
2.81
108
SUSP_JS_Executing_Powershell_Apr23
3.14
274
SUSP_PY_Reverse_Shell_Indicators_Jan23_1
3.25
16
SUSP_OBFUSC_JS_Execute_Base64_Mar23
3.26
34
SUSP_Encoded_Registry_Key_Paths_Sep22_1
3.39
64
SUSP_PE_OK_RU_URL_Jun23
3.59
17
HKTL_Clash_Tunneling_Tool_Aug22_2
3.75
16
SUSP_PY_OBFUSC_Hyperion_Aug22_1
4.0
13
SUSP_BAT_OBFUSC_Apr23_1
4.0
16
SUSP_RANSOM_Note_Aug22
4.01
171
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23_2
4.52
67
SUSP_BAT_PS1_Contents_Jan23_1
5.11
18
SUSP_OBFUSC_PS1_FormatStrings_Dec22_1
5.33
12
SUSP_BAT_OBFUSC_Apr23_4
5.35
26
SUSP_OBFUSC_BAT_Dec22_1
5.84
31

Latest YARA Matches with Low AV Detection Rate

This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)

Rule
AVs
Hash
VT
SUSP_B64_Atob_Aug23
6
a5cebf11bed09e0613c2190dc27f2581118a14a80027993a3226b3562229326b
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
6
a5cebf11bed09e0613c2190dc27f2581118a14a80027993a3226b3562229326b
SUSP_XORed_Mozilla_Oct19
10
c349efdf95d0cc0bd62f50e7ca498296146d63d033a449331e4c350f75a5b943
HKTL_Defeat_Defender_Apr21_1
9
9c64f4c0310e62ddda3c789954862c076e5c783e8077ce604bb8b8a3ed3fc110
SUSP_Defender_Disable_AV_Scanning
9
9c64f4c0310e62ddda3c789954862c076e5c783e8077ce604bb8b8a3ed3fc110
SUSP_Defender_Exclusion_Aug21
9
9c64f4c0310e62ddda3c789954862c076e5c783e8077ce604bb8b8a3ed3fc110
SUSP_PowerShell_Disable_MicrosoftDefender_Features_Jan22_1
9
9c64f4c0310e62ddda3c789954862c076e5c783e8077ce604bb8b8a3ed3fc110
SUSP_EtwEventWrite_Import_Aug21_1
1
68837e2a185782e5305fef18a322428da38c5589afb6876c82ed4cbbe17285be
SUSP_Defender_Disable_AV_Scanning
1
b7c227398ef929826e803fddb3cd811ce38987dbf3a6801eae5b13d7835436f2
SUSP_B64_Atob_Aug23
7
6ccaa24642b3911a8b0f23183c3e25852e4d194588be29e159c53ba6c4834ece
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
7
6ccaa24642b3911a8b0f23183c3e25852e4d194588be29e159c53ba6c4834ece
SUSP_B64_Atob_Aug23
7
0c5a19fa9a590c500833d1c96fa151d54adc1862966f8ac43f468b1cfda850b8
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
7
0c5a19fa9a590c500833d1c96fa151d54adc1862966f8ac43f468b1cfda850b8
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
7
59c67d051e193e60429585e94522e4e254815b0b63115610ae5198b531ca92c8
SUSP_B64_Atob_Aug23
7
59c67d051e193e60429585e94522e4e254815b0b63115610ae5198b531ca92c8
SUSP_B64_Atob_Aug23
7
d35fa5449e2601407ad142ca0ad27719de15ff20def3692e3d0f99ffec11ad94
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
7
d35fa5449e2601407ad142ca0ad27719de15ff20def3692e3d0f99ffec11ad94
APT_MAL_Covenant_Backdoor_Loader_Feb26
8
d3af072d9ddf1d7d678a78b2ee4599ea1cd9a28ac014b9b19746e9bd40475d58
SUSP_EtwEventWrite_Import_Aug21_1
6
3f4c9cdf7ec81fd374bcbf829b8b2f1bc413a1a244afced7ac0e44023626df70
SUSP_AMSI_Bypass_Indicator_Nov22_1
6
3f4c9cdf7ec81fd374bcbf829b8b2f1bc413a1a244afced7ac0e44023626df70

YARA Rules Per Category

This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)

Tag
Count
Malware
7775
Threat Hunting (not subscribable, only in THOR scanner)
5975
APT
5078
Hacktools
4888
Webshells
2404
Exploits
744

Newest Sigma Rules

This table shows the newest additions to the Sigma rule set

Rule
Description
Date
Ref
Info
Potential Ctxmui.DLL Sideloading
Detects potential DLL sideloading of "ctxmui.dll"
12.07.2026
Renamed Solid PDF Creator.EXE Execution
Detects the execution of a renamed Solid PDF Creator binary.
12.07.2026
Scheduled Task Execution with Hardcoded IPv4 Address
Detects a process spawned by the Windows Task Scheduler whose command line contains a hardcoded IPv4 address. This may indicate the execution of a task previously created to reach out to attacker-controlled IP addresses for persistence or exfiltration.
10.07.2026
Scheduled Task Created via Remotely Hosted XML File
Detects schtasks.exe creating a new scheduled task using an XML definition file hosted on a remote UNC path (hostname or IP address). Threat actors may use this technique to load malicious task definitions from attacker-controlled or compromised file shares.
09.07.2026
SQL Server Query Output to File via OSQL.EXE
Detects SQL Server queries that output results to a file using the OSQL utility. This might indicate potential attempts to save sensitive data for exfiltration or for later analysis during post-exploitation activities. Even though this could be executed in legitimate contexts, this warrants immediate investigation.
05.07.2026
VirtualBox Binary Masquerading
Detects execution of binaries using VirtualBox-related filenames which are not the legitimate VirtualBox binaries. This may indicate an attempt to masquerade malicious binaries as VirtualBox components to evade detection.
05.07.2026
VMware Binary Masquerading
Detects execution of binaries using VMware-related filenames but are not the legitimate VMware binaries. This may indicate an attempt to masquerade malicious binaries as VMware components to evade detection.
05.07.2026
Credential Added to Public IPv4 Address via Cmdkey.EXE
Detects the addition of credentials to a public IPv4 address via cmdkey.exe. Adding credential to cmdkey allows attackers to store credentials for later use. Threat Actors may use this technique to access remote systems without being prompted for credentials and use automated scripts more effectively.
05.07.2026
File or Directory Enumeration Via WMIC
Detects file or directory enumeration via WMIC using the Win32_Directory or CIM_DataFile classes. Attackers use these classes to list directories or files on specific drives (e.g., "C:") during post-exploitation reconnaissance - a technique that bypasses traditional dir /ls command monitoring.
01.07.2026
Environment Variable Enumeration Via WMIC
Detects enumeration of environment variables via WMIC using the Win32_Environment class. Attackers query "environment get name,variablevalue" during host reconnaissance to discover paths, usernames, and configuration values useful for lateral movement or payload staging.
01.07.2026
Startup Item Enumeration Via WMIC
Detects enumeration of startup items via WMIC using the Win32_StartupCommand class. Attackers query startup items to discover persistence mechanisms that automatically execute malicious binaries or scripts during system boot or user logon.
01.07.2026
User Account Password Property Manipulation Via WMIC
Detects manipulation of password-related properties on user accounts via WMIC against the Win32_UserAccount class. This covers direct password changes as well as policy modifications such as disabling password expiry or preventing password changes, all common persistence techniques to maintain access to a backdoor account.
01.07.2026
Network Configuration Enumeration Via WMIC NicConfig
Detects enumeration of network interface configuration via WMIC using the "nicconfig" or "nic" aliases. Attackers commonly query NIC configuration during post-exploitation reconnaissance to discover IP addresses, MAC addresses, default gateways, and DNS servers — information used to map the network and pivot to additional targets.
01.07.2026
Suspicious Print Processor Driver Registry Modification
Detects modifications to Windows Print Processor Driver registry values where the configured DLL is not the default winprint.dll. This may indicate abuse of Print Processors for persistence or privilege escalation, as used by malware such as SprySOCKS.
26.06.2026
SOCKS Proxy Tunneling Invocation
Detects processes that invoke SOCKS proxy tunneling via command-line arguments. Threat actors abuse SOCKS-capable tools such as chisel, revsocks, or custom SSH tunnelers to establish covert C2 channels or bypass network controls.
23.06.2026
PowerShell Enumeration of Claude Code Chat History
Detects PowerShell scripts enumerating or reading files within the Claude Code conversation history directory. Claude Code stores conversation history as JSONL files under: %USERPROFILE%\.claude\projects\<hash>\<session>.jsonl Threat actors extract these files and apply regex matching to locate high-value secrets (cloud tokens, private keys, database passwords) before pivoting to infrastructure such as ESXi hosts via harvested SSH credentials.
11.06.2026
PowerShell One-Liner Credential Pattern Search
Detects PowerShell or pwsh one-liners whose command line combines a regex or string-matching primitive with common credential-related keywords. It might indicate an attempt of credential harvesting across local files, including config files, source code, chat history, etc. looking for secrets such as API keys, tokens, passwords, or SSH keys.
11.06.2026
PowerShell One-Liner Targeting Claude Code Chat History
Detects PowerShell one-liners trying to enumerate or read files within the Claude Code conversation history directory. Claude Code stores conversation history as JSONL files under: %USERPROFILE%\.claude\projects\<hash>\<session>.jsonl Threat actors extract these files and apply regex matching to locate high-value secrets (cloud tokens, private keys, database passwords) before pivoting to infrastructure such as ESXi hosts via harvested SSH credentials.
11.06.2026
GitHub Token Access Via GH CLI
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Malicious packages and scripts have been observed using these commands to silently exfiltrate the victim's stored GitHub authentication token.
08.06.2026
GitLab Token Access Via GLAB CLI
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
GitHub Token Access Via GH CLI - Linux
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitHub repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
NPM Package Install Executed From Suspicious Location - Linux
Detects the execution of "npm install" via node on Linux from potentially suspicious directories. It might indicate a malicious package being installed or executed from a non-standard location. Attackers might use npm packages to execute malicious code on the victim's machine, potentially leading to data exfiltration, persistence, or further compromise of the system.
08.06.2026
Node or Bun Execution from Suspicious Locations - Linux
Detects the execution of build tools such as bun and node from potentially suspicious locations on Linux systems. In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute build tools such as bun and node from locations that are not commonly used for legitimate purposes.
08.06.2026
GitLab Token Access Via GLAB CLI - Linux
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
NPM Package Install Executed From Suspicious Location
Detects the execution of "npm install" via node.exe from potentially suspicious directories on Windows systems. It might indicate a malicious package being installed or executed from a non-standard location. Attacker might use npm packages to execute malicious code on the victim's machine, potentially leading to data exfiltration, persistence, or further compromise of the system.
08.06.2026
Node or Bun Execution from Suspicious Locations
Detects the execution of build tools such as bun and node from potentially suspicious locations on Windows systems. In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute build tools such as bun and node from locations that are not commonly used for legitimate purposes.
08.06.2026
NTLM Hash Leak Via Curl NTLM Authentication
Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an attacker-controlled server, enabling offline cracking or relay attacks. When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials stored in LSASS — without requiring a plaintext password. This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
04.06.2026
Uninstall SystemComponent Registry Value Modification via CommandLine
Detects modification of the "SystemComponent" registry value in the "Uninstall" key through command line. Attackers modify this value to hide installed applications from "Programs and Features", often as part of persistence or defense evasion techniques.
04.06.2026
Audit Policy Category Discovery via Auditpol.EXE
Detects the use of auditpol.exe to query audit policy to discover which audit categories are enabled on the system. Attackers may use this information to identify potential gaps in security monitoring and adjust their tactics accordingly. Since, this require elevated privileges, unless it is being used by the administrator for legitimate purposes, it can be considered suspicious and warrants immediate attention.
04.06.2026
Hiding of an Installed Application from Application Wizard
Detects the SystemComponent DWORD registry value being set to 1 under an application's Uninstall key, which removes the application from "Programs and Features" and "Add or Remove Programs" visibility. Threat actors use this technique to hide installed applications, from normal administrative review, as part of persistence or defense evasion strategies.
04.06.2026

YARA/SIGMA Rule Count

Rule Type
Community Feed
Nextron Private Feed
Yara
1391
22972
Sigma
3591
1064

Sigma Rules Per Category (Community)

Type
Count
windows / process_creation
1351
windows / registry_set
219
windows / file_event
209
windows / ps_script
166
windows / security
160
linux / process_creation
139
windows / image_load
114
webserver
82
windows / system
74
macos / process_creation
69
aws / cloudtrail
55
proxy
54
windows / network_connection
53
linux / auditd
53
azure / activitylogs
42
windows / registry_event
40
azure / auditlogs
38
windows / ps_module
33
windows / application
32
windows / dns_query
27
windows / process_access
25
opencanary / application
24
azure / signinlogs
24
okta / okta
22
windows / pipe_created
19
azure / riskdetection
19
rpc_firewall / application
17
windows / windefend
17
linux
16
gcp / gcp.audit
16
github / audit
15
linux / file_event
15
bitbucket / audit
14
m365 / threat_management
13
cisco / aaa
13
windows / file_delete
13
windows / create_remote_thread
12
windows / codeintegrity-operational
10
dns
10
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / ps_classic_start
9
windows / appxdeployment-server
9
windows / create_stream_hash
9
windows / firewall-as
8
windows / msexchange-management
8
gcp / google_workspace.admin
7
zeek / smb_files
7
antivirus
7
fortigate / event
7
azure / pim
7
windows / file_access
7
windows / bits-client
7
windows / dns-client
6
kubernetes / audit
6
linux / network_connection
5
zeek / http
5
jvm / application
5
zeek / dns
5
m365 / audit
4
windows / sysmon
4
macos / file_event
4
windows / taskscheduler
4
windows / iis-configuration
4
zeek / dce_rpc
4
windows / registry_add
3
gcp / google_workspace.login
3
linux / sshd
3
windows / wmi_event
3
windows / powershell-classic
3
windows / ntlm
3
linux / syslog
2
windows / security-mitigations
2
spring / application
2
windows / dns-server
2
apache
2
onelogin / onelogin.events
2
firewall
2
paloalto / appliance / globalprotect
1
windows / certificateservicesclient-lifecycle-system
1
windows / shell-core
1
python / application
1
zeek / x509
1
windows / smbclient-security
1
windows / file_executable_detected
1
windows / sysmon_status
1
m365 / exchange
1
zeek / rdp
1
windows / diagnosis-scripted
1
windows / file_rename
1
ruby_on_rails / application
1
zeek / kerberos
1
windows / terminalservices-localsessionmanager
1
windows / sysmon_error
1
velocity / application
1
m365 / threat_detection
1
windows / driver-framework
1
sql / application
1
linux / sudo
1
cisco / duo
1
cisco / ldp
1
nginx
1
windows
1
windows / dns-server-analytic
1
cisco / bgp
1
windows / ldap
1
windows / wmi
1
windows / ps_classic_provider_start
1
windows / printservice-operational
1
database
1
windows / printservice-admin
1
linux / clamav
1
windows / lsa-server
1
django / application
1
linux / auth
1
linux / cron
1
windows / appmodel-runtime
1
fortios / sslvpnd
1
linux / guacamole
1
juniper / bgp
1
windows / applocker
1
windows / openssh
1
windows / process_tampering
1
cisco / syslog
1
huawei / bgp
1
windows / appxpackaging-om
1
windows / smbclient-connectivity
1
windows / smbserver-connectivity
1
windows / raw_access_thread
1
nodejs / application
1
paloalto / file_event / globalprotect
1
linux / vsftpd
1
windows / capi2
1
windows / microsoft-servicebus-client
1
windows / file_change
1

Sigma Rules Per Category (Nextron Private Feed)

Type
Count
windows / process_creation
529
windows / registry_set
93
windows / ps_script
89
linux / process_creation
59
windows / file_event
49
windows / image_load
48
windows / wmi
29
windows / security
29
windows / system
13
proxy
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ps_module
5
windows / dns_query
5
windows / ntfs
5
webserver
4
windows / taskscheduler
4
windows / create_remote_thread
4
windows / registry_delete
4
windows / sense
4
windows / pipe_created
4
windows / ps_classic_script
3
windows / vhd
3
windows / application-experience
3
windows / hyper-v-worker
3
windows / driver_load
3
macos / process_creation
3
dns
3
windows / smbclient-security
2
windows / windefend
2
windows / process_access
2
windows / kernel-shimengine
2
windows / file_access
2
linux / file_event
2
windows / file_delete
2
windows / bits-client
2
windows / codeintegrity-operational
2
linux / Linux kernel module / THOR
2
linux / Unix user / THOR
1
windows / application
1
windows / amsi
1
windows / posh_ps
1
windows / audit-cve
1
windows / environment variable / THOR
1
windows / registry-setinformation
1
linux / file_delete
1
windows / firewall-as
1
windows / file_rename
1

Tenable Nessus

Requirement: Privileged Scan

  • YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
Tutorial: https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

YARA Scanning with Nessus

  • You can only upload a single .yar file
  • Filesystem scan has to be activated
  • You have to define the target locations
  • The Nessus plugin ID will be 91990
  • Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
Tutorial: https://de.tenable.com/blog/threat-hunting-with-yara-and-nessus

Carbon Black

Tutorial: https://github.com/carbonblack/cb-yara-connector

FireEye EX

Tutorial: https://www.fireeye.com/blog/products-and-services/2018/12/detect-and-block-email-threats-with-custom-yara-rules.html