Valhalla Logo
currently serving 24422 YARA rules and 4689 Sigma rules
API Key

New Rules per Day

Newest YARA Rules

This table shows the newest additions to the YARA rule set

Rule
Description
Date
Ref
MAL_JS_Shai_Hulud_Aug26
Detects malicious JavaScript used to steal GitHub credentials
04.08.2026
SUSP_OBFUSC_JS_Patterns_Aug26_1
Detects common obfuscation patterns in JavaScript seen being used by Lazarus Group (DPRK)
03.08.2026
SUSP_OBFUSC_JS_Patterns_Aug26_2
Detects common obfuscation patterns in JavaScript seen being used by Lazarus Group (DPRK)
03.08.2026
SUSP_PY_Credential_Stealer_Aug26
Detects credential stealer written in Python which exfiltrates SSH keys and API tokens
03.08.2026
MAL_GoGRPC_Aug26_1
Detects GoGRPC, a Go-based backdoor
02.08.2026
MAL_GoGRPC_Aug26_2
Detects GoGRPC, a Go-based backdoor
02.08.2026
MAL_RevSocket_Aug26
Detects RevSocket, a Go-based reverse SOCKS proxy
02.08.2026
MAL_RSOX_Aug26
Detects RSOX, a Rust-based tool that acts as a SOCKS proxy relay
02.08.2026
MAL_TriBackLoader_Aug26
Detects TriBackLoader, a custom shellcode loader
02.08.2026
MAL_EXP_Email_CVEs_Aug26
Detects multiple CVEs exploiting webmail vulnerabilities such as CVE-2026-8496
02.08.2026
MAL_ZimReaper_Aug26
Detects ZimReaper that steals the Cross-Site Request Forgery (CSRF) token and the auto-complete password of the logged-in user from the browser, then uses Zimbra APIs to conduct reconnaissance against the device and gather two-factor authentication codes. This material is exfiltrated alongside the victim's email address, and information about the Zimbra installation, via DNS queries to the adversary C&C.
02.08.2026
MAL_Roundcube_Credential_Stealer_Aug26
Detects Roundcube credential stealer module
02.08.2026
SUSP_Encoded_JavaScript_Execution_Aug26
Detects entity-encoded and URI/Unicode-escaped JavaScript to dynamically reconstruct and execute JavaScript
02.08.2026
MAL_APT_NightLedger_Aug26
Detects NightLedger backdoor, attributed to Mirage Kitten APT
01.08.2026
MAL_CVE_2025_66376_Aug26_2
Detects CVE-2025-66376, that does not adequately sanitize items between @import calls.
01.08.2026
SUSP_CVE_2025_66376_Aug26_1
Detects CVE-2025-66376, that does not adequately sanitize items between @import calls.
01.08.2026
SUSP_Kernel_Module_SpcSpOpusInfo_Jul26
Detects a kernel module signed by Autel Intelligent Technology Corp., Ltd., which has been observed to be associated with suspicious activity.
31.07.2026
SUSP_External_DTD_File_Exfiltration_Jul26
Detects DTD file containing entity declarations commonly used to read sensitive file content to be exfiltrated. Further investigation recommended.
28.07.2026
SUSP_WEBSHELL_PHP_Indicators_Jul26
Detects indicators often found in PHP webshells
28.07.2026
MAL_OBFUSC_Eval_Jul26
Detects obfuscated eval often found in PHP webshells
28.07.2026
MAL_HelloInjector_Jul26
Detects HelloInjector, a loader that uses syscalls to inject HelloProxy backdoor
28.07.2026
MAL_HelloProxy_Backdoor_Jul26
Detects HelloProxy, a proxy and a loader that hooks NtDeviceIoControlFile/closesocket/shutdown to intercept AFD-layer socket I/O, authenticates C2 connections via SOCKS5, capable of deploying additional payloads
28.07.2026
SUSP_GO_Packer_Jul26
Detects packed Go binaries, which are often used for malware distribution
28.07.2026
SUSP_LNK_Jul26_1
Detects LNK which points to VBS script and potential lure PDF
28.07.2026
MAL_LNK_FTP_Jul26
Detects LNK which use ftp.exe -s to execute malicious payloads
28.07.2026
HKTL_LegacyHive_Jul26
Detects privilege escalation attempts via Legacy Hive exploiting Windows User Profile Service hive load vulnerability.
28.07.2026
MAL_APT_Shellcode_Loader_Jul26
Detects a shellcode loader that uses a custom XOR based decryption routine to load and execute shellcode from memory, seen being used by OceanLotus APT group
27.07.2026
MAL_PeatWire_SharePoint_Backdoor_Jul26
Detects PEATWIRE SharePoint backdoor variants that abuse the SignOut page to access ASP.NET MachineKey material for authentication abuse and persistent access.
27.07.2026
EXPL_PS1_CVE_2026_50522_Jul26
Detects proof-of-concept PowerShell script exploiting CVE-2026-50522
23.07.2026
MAL_Havoc_Terminator_ShellCode_Jul26
Detects shellcode used to load Havoc Terminator, a hacktool used to terminate security processes by abusing a vulnerable driver capable of terminating processes in kernel mode
22.07.2026

Successful YARA Rules in Set

This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)

Rule
Average AV Detection Rate
Sample Count
Info
VT
MAL_GuLoader_Shellcode_Oct22_3
0.0
20
SUSP_MAL_EXFIL_Stealer_Output_Characteristics_Sep22_1
0.04
180
SUSP_PY_OBFUSC_Berserker_Indicators_Dec22_1
0.21
14
SUSP_BAT_OBFUSC_Apr23_2
0.59
64
SUSP_Encrypted_ZIP_Suspicious_Contents_Jul23_1_File
0.64
11
SUSP_PUA_RustDesk_Apr23_1
0.68
22
SUSP_BAT_PS1_Combo_Jan23_2
0.71
45
SUSP_JS_OBFUSC_Feb23_2
1.04
1736
SUSP_WEvtUtil_ClearLogs_Sep22_1
1.12
43
SUSP_CryptBase_PE_Info_NOT_Cryptbase_Feb23
1.19
21
SUSP_OBFUSC_PY_Loader_Jun23_1
1.48
21
SUSP_Webshell_OBFUSC_Indicators_Aug22_1
2.07
14
SUSP_URL_Split_Jun23
2.5
18
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23
2.69
13
PUA_RuskDesk_Remote_Desktop_Jun23_1
2.78
18
SUSP_JS_Redirector_Mar23
2.81
108
SUSP_JS_Executing_Powershell_Apr23
3.14
274
SUSP_PY_Reverse_Shell_Indicators_Jan23_1
3.25
16
SUSP_OBFUSC_JS_Execute_Base64_Mar23
3.26
34
SUSP_Encoded_Registry_Key_Paths_Sep22_1
3.39
64
SUSP_PE_OK_RU_URL_Jun23
3.59
17
HKTL_Clash_Tunneling_Tool_Aug22_2
3.75
16
SUSP_PY_OBFUSC_Hyperion_Aug22_1
4.0
13
SUSP_BAT_OBFUSC_Apr23_1
4.0
16
SUSP_RANSOM_Note_Aug22
4.01
171
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23_2
4.52
67
SUSP_BAT_PS1_Contents_Jan23_1
5.11
18
SUSP_OBFUSC_PS1_FormatStrings_Dec22_1
5.33
12
SUSP_BAT_OBFUSC_Apr23_4
5.35
26
SUSP_OBFUSC_BAT_Dec22_1
5.84
31

Latest YARA Matches with Low AV Detection Rate

This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)

Rule
AVs
Hash
VT
SUSP_PS1_OFBUSC_XOR_Encryption_Aug23
14
d611a1aeb7bbf3fc7ce505d6dc9b12d83b1d73cc4bace725b8c4d8bb762a489c
SUSP_PS1_ProcessMemory_Mods_Jul21_3
12
8b2cbcbbee9b7030283a1ae010e91c8e6e37f189b92d0b88bbbaa446f93daf04
SUSP_MSIL_NET_ConfuserEx_Module_Encryption_Sep23
9
b81aa7771918635969fdb94e365fb6d3604d969d152af6d4514916b35c95007f
MAL_PY2EXE_Downloader_May20_1
2
9a8e21d59fcbf247f2455b7c554e31e889ea6764d7fc470bd631361c1cfe8b09
SUSP_Script_IP_Info_Combo_Aug24
4
a16b062d56353dcda3e8e82df8eea2859eeac4137b7147ed65f42cef326752e4
SUSP_OBFUSC_PY_Function_Combo_Encoded_Aug25_4
4
a759a37e57a42d876e07d3d2fa30cf9803b4ca2002c6f8b51d15eca34817af3f
HKTL_PY_Bypass_Tool_Aug21_2
4
a759a37e57a42d876e07d3d2fa30cf9803b4ca2002c6f8b51d15eca34817af3f
SUSP_Double_Base64_Encoded_Strings_Dec20_File
4
a759a37e57a42d876e07d3d2fa30cf9803b4ca2002c6f8b51d15eca34817af3f
SUSP_Base64_Encoded_WScriptShell
6
abd0378d9b7bf112200f804b9fb5048f2ddc39ee493a99dca5acab6da2f1907b
SUSP_Base64_Encoded_WhomAmI_Wide
6
abd0378d9b7bf112200f804b9fb5048f2ddc39ee493a99dca5acab6da2f1907b
SUSP_Encoded_WinDefend_Feb22_1
6
abd0378d9b7bf112200f804b9fb5048f2ddc39ee493a99dca5acab6da2f1907b
SUSP_OBFUSC_PS1_Encoded_PowerShell_Commands_Apr22_1
6
abd0378d9b7bf112200f804b9fb5048f2ddc39ee493a99dca5acab6da2f1907b
SUSP_Encoded_Registry_Key_Paths_Sep22_1
6
abd0378d9b7bf112200f804b9fb5048f2ddc39ee493a99dca5acab6da2f1907b
SUSP_PS1_Encoded_Defender_AV_Exclusion_Pattern_Mar22_1
6
abd0378d9b7bf112200f804b9fb5048f2ddc39ee493a99dca5acab6da2f1907b
SUSP_Chrome_Stealer_Indicators_Oct24_1
6
86bc1d8487f4c48e917af8a25427192a4fea7a77aa9780fc8c15faabbd77f78c
SUSP_Go_Binary_Function_Name_Feb25
3
8c061e639cfa6435117bbe7095dd60dcb507d41df7bfb9ec68b60de8958a5048
SUSP_EtwEventWrite_Import_Aug21_1
1
af2180da7620c74a7f1c51c6c3c721c3ede5e3dac4125b1ac06d34eb0f1aed55
SUSP_OBFUSC_Reversed_String_Mar15
1
b19e7b4e25657606b83bb8ca4613d1d5357ff8bb5bd37a38c12154e03f6d3fd3
SUSP_Github_Repo_Name_Mar25
5
d05389111470802b9140240aaf6739088dbe36cc7955ba1f0fda025348acc336
SUSP_Deadbeef_Info
5
d05389111470802b9140240aaf6739088dbe36cc7955ba1f0fda025348acc336

YARA Rules Per Category

This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)

Tag
Count
Malware
7806
Threat Hunting (not subscribable, only in THOR scanner)
5996
APT
5082
Hacktools
4891
Webshells
2405
Exploits
746

Newest Sigma Rules

This table shows the newest additions to the Sigma rule set

Rule
Description
Date
Ref
Info
ADCS - Certighost Ghost Machine Account Creation
Detects the creation of a machine account whose name starts with 'GHOST', which is the naming convention used by the CVE-2026-54121 (Certighost) exploit tooling. The public proof-of-concept for Certighost creates a temporary machine account with a name of the form GHOST<random>$ before enrolling for a DC certificate via the cdc chase path. The attacker-controlled machine account is used as the requester identity in the certificate request; the cdc attribute then redirects the CA to a rogue host that returns a forged Domain Controller identity. The resulting certificate carries the DC's SID and DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync. A machine account creation event (4741) where TargetUserName starts with 'GHOST' and ends with '$' is a high-fidelity indicator of this attack tool's execution. Legitimate environments very rarely provision machine accounts with this prefix.
30.07.2026
ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121)
Detects Active Directory Certificate Services (ADCS) certificate requests that include the 'cdc' (Client DC) request attribute pointing to a domain or IP that is not a known Domain Controller. 'cdc' is an optional MS-WCCE enrollment attribute designed for cross-domain/cross-forest scenarios where a client in a child domain tells the CA which DC to contact for identity lookups when the CA cannot reach that domain directly. Legitimate values are DC hostnames or IPs that resolve to a real Domain Controller computer object in AD with the SERVER_TRUST_ACCOUNT (0x2000) userAccountControl bit set. In an attack, the attacker sets cdc to a domain or IP they control so the CA connects to their rogue SMB and LDAP services instead of a real DC. The rogue server returns a forged DC identity which the pre-patch CA accepts without validation. A malicious event looks like: Requester: DOMAIN\GHOST<random>$ Attributes: cdc:<attacker_ip> rmd:<target_dc_fqdn> SubjectAlternativeName: DNS Name=<target_dc_fqdn> CVE-2026-54121 (Certighost) is the known exploit for this path. The July 2026 patch added _ValidateChaseTargetIsDC which rejects cdc values that do not resolve to a legitimate DC object in Active Directory before following the chase.
27.07.2026
ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121)
Detects successful issuance of an ADCS certificate where the request attributes include 'cdc' (Client DC) or 'rmd' (Remote Domain) pointing to a non-DC domain or IP, confirming the CA's chase fallback path was taken against an attacker-controlled target. 'cdc' directs the CA to an address for identity lookup; 'rmd' specifies the principal to look up there. In an attack (CVE-2026-54121, Certighost), cdc points to a rogue host that returns a forged DC identity. A successfully issued certificate at this stage means the attacker has obtained a cert carrying a Domain Controller's SID and DNS identity, enabling PKINIT authentication as that DC followed by DCSync replication.
27.07.2026
Registry Hive File Staged Outside Standard User Profile Path
Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path. These files generally contain various user-specific registry settings and are typically located in the user's profile directory. Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings for persistence, privilege escalation, or dump user registry hives for credential harvesting.
23.07.2026
Suspicious Cross-User Process Spawn
Detects suspicious spawning of a process under a different user context than the parent process. Processes such as notepad.exe, calculator etc. are generally spawned under the same user context and also they are often targeted as sacrificial process or decoy process to check successful privilege escalation.
23.07.2026
Potentially Suspicious Explicit Credential Local Logon
Detects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account.
23.07.2026
Potentially Suspicious Image Load of Offreg.dll
Detects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs.
23.07.2026
AppDomainManager Environment Variable Hijack - PsScript
Detects the usage of environment variables related to the .NET AppDomainManager within PowerShell scripts. The presence of these variables in script content may indicate attempts to hijack the AppDomainManager, allowing adversaries to execute malicious code within trusted processes. Setting these variables in scripts can force legitimate .NET applications to load attacker-controlled assemblies, enabling stealthy code execution and persistence.
20.07.2026
AppDomainManager Environment Variable Hijack
Detects the use of environment variables related to the .NET AppDomainManager, which can be hijacked by adversaries to execute malicious code within trusted processes. Adversaries can set these variables to point to a malicious assembly, forcing legitimate .NET applications to load it upon startup. This technique allows for stealthy code execution within trusted, signed processes.
20.07.2026
Modification of AppDomain Manager Environment Variables
Detects modification of AppDomain Manager environment variables in the registry, which can be abused to hijack .NET AppDomain Manager. Adversaries can set these variables to point to a malicious assembly, causing any legitimate .NET applications to load it upon startup, enabling stealthy code execution.
20.07.2026
NET Config File Creation in Suspicious Location
Detects .NET configuration files (.exe.config) with potential AppDomainManager hijack patterns being created in suspicious or non-standard locations. Adversaries may create or modify .NET configuration files in non-standard locations to hijack the AppDomainManager, which is responsible for managing application domains in the .NET framework.
20.07.2026
NET Config File Creation by Potentially Suspicious Process
Detects .NET configuration files (.exe.config) with potential AppDomainManager hijack patterns being created by suspicious processes such as scripting engines, downloaders, or interpreters. Adversaries may use these processes to drop .NET configuration files that hijack the AppDomainManager, which is responsible for managing application domains in the .NET framework.
20.07.2026
Suspicious Creation of .NET Binaries or Configs Outside Legitimate Paths
Detects creation of .NET framework binaries or configuration files outside of legitimate installation paths. It might indicate attempts to establish persistence or execute malicious code using the AppDomainManager technique. In this technique, adversaries may create or modify .NET binaries or configuration files in non-standard locations to hijack the AppDomainManager, which is responsible for managing application domains in the .NET framework. This can allow attackers to execute malicious code with elevated privileges or maintain persistence on a compromised system.
20.07.2026
WordPress Wp2shell Exploitation Tool User-Agent
Detects the hardcoded "wp2shell" User-Agent string used by the wp2shell PoC tool during all phases of CVE-2026-63030 and CVE-2026-60137 exploitation.
19.07.2026
WordPress Wp2shell REST Batch Endpoint Exploitation
Detects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target.
19.07.2026
WordPress Wp2shell Webshell Plugin Access
Detects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence.
19.07.2026
Inverted LOLBin Executable Strings in CommandLine
Detects reversed/inverted living-off-the-land binary (LOLBin) executable names in command line arguments. Adversaries may reverse binary name strings to bypass signature-based detection that matches plain-text LOLBin names.
17.07.2026
Inverted Malware-Abused Path Strings in CommandLine
Detects reversed/inverted strings of writable Windows directories commonly abused by malware as staging, persistence, or execution locations. Adversaries may reverse path strings to bypass static path-based detection signatures.
17.07.2026
Inverted Windows System Path Strings in CommandLine
Detects reversed/inverted strings of Windows system directory paths in command line arguments. Adversaries may reverse path strings to conceal references to system directories and bypass static string-based detection.
17.07.2026
Suspicious Execution of Windows Defender Critical Binaries
Detects suspicious execution of Windows Defender Binaries either executed from an unusual location or binary trying to masquerade as a legitimate Windows Defender binary. This behavior can be indicative of an attacker trying to hide their malicious binary by masquerading as a legitimate Windows Defender binary or some exploit trying to bypass Windows Defender.
15.07.2026
AllowedProcessName Registry Value Modification
Detects modification of an `AllowedProcessName` registry value under any Windows service key. Some kernel drivers and privileged services use registry-configured process paths to determine which applications are permitted to access sensitive functionality. An attacker with registry write access may modify this value to reference an attacker-controlled executable, causing the associated component to treat the malicious process as trusted. Successful abuse could grant access to privileged operations exposed by the component, such as reading protected process memory, terminating processes, or interfering with security software.
15.07.2026
Potential Ctxmui.DLL Sideloading
Detects potential DLL sideloading of "ctxmui.dll"
12.07.2026
Renamed Solid PDF Creator.EXE Execution
Detects the execution of a renamed Solid PDF Creator binary.
12.07.2026
AWS Bedrock Guardrail Updated
Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and allow unsafe or unauthorized model responses.
10.07.2026
AWS Bedrock Guardrail Deleted
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety controls and allow unsafe or unauthorized model responses.
10.07.2026
Scheduled Task Execution with Hardcoded IPv4 Address
Detects a process spawned by the Windows Task Scheduler whose command line contains a hardcoded IPv4 address. This may indicate the execution of a task previously created to reach out to attacker-controlled IP addresses for persistence or exfiltration.
10.07.2026
Scheduled Task Created via Remotely Hosted XML File
Detects schtasks.exe creating a new scheduled task using an XML definition file hosted on a remote UNC path (hostname or IP address). Threat actors may use this technique to load malicious task definitions from attacker-controlled or compromised file shares.
09.07.2026
SQL Server Query Output to File via OSQL.EXE
Detects SQL Server queries that output results to a file using the OSQL utility. This might indicate potential attempts to save sensitive data for exfiltration or for later analysis during post-exploitation activities. Even though this could be executed in legitimate contexts, this warrants immediate investigation.
05.07.2026
VMware Binary Masquerading
Detects execution of binaries using VMware-related filenames but are not the legitimate VMware binaries. This may indicate an attempt to masquerade malicious binaries as VMware components to evade detection.
05.07.2026
VirtualBox Binary Masquerading
Detects execution of binaries using VirtualBox-related filenames which are not the legitimate VirtualBox binaries. This may indicate an attempt to masquerade malicious binaries as VirtualBox components to evade detection.
05.07.2026

YARA/SIGMA Rule Count

Rule Type
Community Feed
Nextron Private Feed
Yara
1391
23031
Sigma
3614
1075

Sigma Rules Per Category (Community)

Type
Count
windows / process_creation
1357
windows / registry_set
219
windows / file_event
211
windows / ps_script
166
windows / security
164
linux / process_creation
142
windows / image_load
115
webserver
86
windows / system
74
macos / process_creation
69
aws / cloudtrail
57
proxy
55
linux / auditd
54
windows / network_connection
53
azure / auditlogs
44
windows / registry_event
40
azure / activitylogs
35
windows / ps_module
33
windows / application
32
windows / dns_query
28
windows / process_access
25
opencanary / application
24
okta / okta
22
azure / riskdetection
19
windows / pipe_created
19
azure / signinlogs
18
rpc_firewall / application
17
windows / windefend
17
linux
16
linux / file_event
16
gcp / gcp.audit
16
github / audit
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / appxdeployment-server
9
antivirus
9
windows / ps_classic_start
9
windows / create_stream_hash
9
windows / firewall-as
8
windows / msexchange-management
8
windows / file_access
7
azure / pim
7
windows / bits-client
7
gcp / google_workspace.admin
7
zeek / smb_files
7
fortigate / event
7
kubernetes / audit
6
windows / dns-client
6
jvm / application
5
zeek / dns
5
linux / network_connection
5
zeek / http
5
zeek / dce_rpc
4
m365 / audit
4
windows / sysmon
4
macos / file_event
4
windows / taskscheduler
4
windows / iis-configuration
4
windows / registry_add
3
linux / sshd
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
windows / ntlm
3
linux / syslog
2
windows / security-mitigations
2
windows / dns-server
2
spring / application
2
apache
2
windows / wmi
2
onelogin / onelogin.events
2
windows / applocker
2
firewall
2
fortios / sslvpnd
1
linux / cron
1
huawei / bgp
1
windows / openssh
1
windows / process_tampering
1
cisco / syslog
1
windows / appxpackaging-om
1
windows / smbclient-connectivity
1
juniper / bgp
1
windows / smbserver-connectivity
1
windows / file_change
1
paloalto / file_event / globalprotect
1
windows / capi2
1
windows / shell-core
1
windows / raw_access_thread
1
nodejs / application
1
paloalto / appliance / globalprotect
1
zeek / x509
1
windows / certificateservicesclient-lifecycle-system
1
windows / microsoft-servicebus-client
1
python / application
1
linux / vsftpd
1
windows / file_executable_detected
1
windows / diagnosis-scripted
1
windows / file_rename
1
windows / sysmon_error
1
zeek / rdp
1
windows / smbclient-security
1
windows / terminalservices-localsessionmanager
1
velocity / application
1
m365 / exchange
1
zeek / kerberos
1
windows / sysmon_status
1
m365 / threat_detection
1
windows / driver-framework
1
windows
1
ruby_on_rails / application
1
linux / sudo
1
sql / application
1
cisco / duo
1
cisco / bgp
1
nginx
1
windows / dns-server-analytic
1
windows / ldap
1
windows / ps_classic_provider_start
1
windows / printservice-admin
1
database
1
cisco / ldp
1
windows / lsa-server
1
windows / printservice-operational
1
linux / clamav
1
django / application
1
linux / auth
1
linux / guacamole
1
windows / appmodel-runtime
1

Sigma Rules Per Category (Nextron Private Feed)

Type
Count
windows / process_creation
534
windows / registry_set
95
windows / ps_script
90
linux / process_creation
59
windows / file_event
52
windows / image_load
48
windows / security
29
windows / wmi
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ntfs
5
windows / ps_module
5
windows / dns_query
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / create_remote_thread
4
windows / registry_delete
4
macos / process_creation
3
dns
3
windows / ps_classic_script
3
windows / application-experience
3
windows / vhd
3
windows / hyper-v-worker
3
windows / driver_load
3
windows / kernel-shimengine
2
linux / Linux kernel module / THOR
2
windows / smbclient-security
2
windows / windefend
2
windows / process_access
2
windows / bits-client
2
windows / codeintegrity-operational
2
linux / file_event
2
windows / file_access
2
windows / file_delete
2
windows / file_rename
1
windows / environment variable / THOR
1
linux / Unix user / THOR
1
windows / posh_ps
1
windows / amsi
1
windows / audit-cve
1
windows / firewall-as
1
windows / registry-setinformation
1
linux / file_delete
1
windows / application
1

Tenable Nessus

Requirement: Privileged Scan

  • YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
Tutorial: https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

YARA Scanning with Nessus

  • You can only upload a single .yar file
  • Filesystem scan has to be activated
  • You have to define the target locations
  • The Nessus plugin ID will be 91990
  • Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
Tutorial: https://de.tenable.com/blog/threat-hunting-with-yara-and-nessus

Carbon Black

Tutorial: https://github.com/carbonblack/cb-yara-connector

FireEye EX

Tutorial: https://www.fireeye.com/blog/products-and-services/2018/12/detect-and-block-email-threats-with-custom-yara-rules.html