Valhalla Logo
currently serving 24639 YARA rules and 4724 Sigma rules
API Key

New Rules per Day

Newest YARA Rules

This table shows the newest additions to the YARA rule set

Rule
Description
Date
Ref
MAL_Animate_Clipper_Sep26
Detects Animate Clipper which targets cryptocurrency wallets and other credentials. The malware may also execute additional payloads received from a remote server.
30.09.2026
SUSP_LNX_PAM_Potential_Backdoor_Sep26
Detects potential PAM backdoor activity on Linux. This PAM module's pam_sm_authenticate function may be tampered with to bypass authentication.
30.09.2026
SUSP_WebArchive_Pipe_To_Interpreter_Sep26
Detects scripts that fetch a payload through the Internet Archive's Wayback Machine (web.archive.org) and pipe it into an interpreter or shell, as seen in the DirtyBlanket npm package campaign
29.09.2026
SUSP_LNX_Systemd_Service_Tor_SOCKS_Proxy_Sep26
Detects systemd service units which route the service's traffic through a local Tor SOCKS proxy (port 9050/9150) via proxy environment variables, as seen in the DirtyBlanket npm campaign to hide C2 communication
29.09.2026
WEBSHELL_CSS_PassThrough_Sep26
Detects suspicious CSS files that contain pass-through and cookie decoding functionality, which is often used in webshells
28.09.2026
EXPL_CVE_2026_88772_POC_Sep26
Detects POC for Citrix NetScaler DTLS memory overflow, CVE-2026-88772
28.09.2026
LOG_SUSP_EXPL_CVE_2026_88771_Sep26
Detects potential exploitation indicator for Citrix NetScaler PreAuth Command Injection CVE-2026-88771
28.09.2026
MAL_Remus_Stealer_Sep26
Detects Remus stealer malware. Remus is a stealthy information stealer specialized in credential and crypto wallet harvesting.
28.09.2026
MAL_Generic_Loader_Sep26
Detects a loader used to load other payloads
26.09.2026
SUSP_FNV_1A_Hashing_Sep26
Detects FNV-1a hashing patterns, often used for dynamic function resolution, commonly seen in shellcodes and packers
25.09.2026
MAL_Backdoor_Loader_Sep26
Detects a loader used to load 2nd stage payloads, also seen being used to load SparroWocky backdoor
25.09.2026
MAL_APT_SparroWock_Backdoor_Sep26
Detects SparroWocky backdoor, a backdoor that uses named pipes for C2 communication and can execute commands on the infected system, seen being used by FamousSparrow APT
25.09.2026
MAL_SectopRAT_Shellcode_Loader_Sep26
Detects shellcode used to load SectopRAT
25.09.2026
MAL_Lnk_Downloader_Sep26
Detects malicious .lnk files used to download and execute payloads
25.09.2026
SUSP_MS_Crypto_In_Unusual_Executable_Sep26
Detects the use of LsCsp_EncryptHwid in unusual executables, the function should exclusively be used by executables related to Microsoft Remote Desktop services.
24.09.2026
APT_MAL_RAT_Sep26
Detects a RAT that establishes persistence, communicates with C2 infrastructure, collects system information, and supports remote file download and execution, seen being used by Transparent tribe APT group
22.09.2026
APT_MAL_Famous_Chollima_Branchlure_Git_Hook_Downloader_Sep26
Detects a Git hook downloader's platform-specific delivery endpoint, seen being used by Famous Chollima APT
22.09.2026
APT_MAL_Famous_Chollima_Branchlure_BAT_Launcher_Sep26
Detects Windows batch launcher that stages the next-stage script and runs it, seen being used by Famous Chollima APT
22.09.2026
APT_MAL_Famous_Chollima_Branchlure_Keylogger_Sep26
Detects a keylogger through compiled CIL instruction sequences, seen being used by Famous Chollima APT
22.09.2026
APT_MAL_Famous_Chollima_Branchlure_Node_Spawn_Loader_Sep26
Detects Node loader that spawns a per-platform download piped into an interpreter, seen being used by Famous Chollima APT
22.09.2026
MAL_DLL_Backdoor_Sep26
Detects a DLL backdoor that establishes persistence key, implements anti analysis checks, and communicates with a C2, likely targeting of an Afghanistan government agency
21.09.2026
SUSP_Shell_Loader_Sep26
Detects a loader script that decodes Base64 encoded content and executes the resulting payload via eval
21.09.2026
SUSP_Shell_Downloader_Sep26
Detects a shell downloader script that uses printf-based string reconstruction, gathers the username, and downloads a payload
21.09.2026
MAL_Amos_Stealer_Sep26
Detects Amos stealer
21.09.2026
SUSP_Screen_Capture_Indicators_Sep26
Detects scripts or binaries containing code indicative of screen capture. It doesn't automatically mean the script or binary is malicious, so further analysis is required
16.09.2026
HKTL_BYOVD_Sep26
Detects BYOVD (Bring Your Own Vulnerable Driver) component that loads unsigned kernel shellcode from registry
09.09.2026
MAL_Backdoor_Sep26
Detects a small backdoor capable of command execution, payload writing, and singleton execution checks
09.09.2026
MAL_ShadowHVNC_Family_Sep26
Detects ShadowHVNC and derived variants of it. ShadowHVNC is a stealthy remote access trojan that provides hidden VNC access to compromised systems.
09.09.2026
HKTL_MSNightmare_ShieldCrash_Sep26
Detects ShieldCrash a new iteration of the Microsoft Defender exploit ShieldBreak. The hacktool is used to bypass Windows Defender and execute arbitrary code on the system.
09.09.2026
MAL_MacOS_Downloader_Sep26
Detects a downloader used to retrieve and execute staged payloads from a C2 server.
09.09.2026

Successful YARA Rules in Set

This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)

Rule
Average AV Detection Rate
Sample Count
Info
VT
SUSP_JS_WebSocket_Overwrite_Dec25
0.0
55
HKTL_Kali_Liunx_Virtual_Machine_Jan26
0.0
13
SUSP_RMM_Velociraptor_Configuration_Jan26
0.0
40
SUSP_JS_XMLHttpRequest_Overwrite_Dec25
0.02
186
PUA_NinjaOne_RMM_Jan26
0.15
20
SUSP_BATCH_Downloader_Jan26
0.54
13
PUA_Tailcat_Sep26
0.57
70
SUSP_Base64_Encoded_JavaClass_Nov25
0.64
11
SUSP_EXPL_Filename_Indicators_Dec25
0.82
247
SUSP_EXPL_POC_Code_Indicators_May26_1
0.9
30
MAL_Implant_Indicators_Jul26
1.0
39
SUSP_Exploit_Indicators_Oct25
1.24
1323
SUSP_LNK_WScript_Execution_May26
1.54
186
SUSP_PS1_OBFUSC_Patterns_Nov25_1
1.79
130
SUSP_PY_Exploit_Code_Oct25
2.01
819
SUSP_PE_Embedded_In_Image_File_Oct25
2.17
12
SUSP_PY_Function_Names_Oct25
2.17
919
SUSP_HKTL_POC_Feb26_1
2.44
57
SUSP_PY_OBFUSC_Loader_Indicators_Nov25_2
2.6
15
SUSP_PY_Suspicious_Functions_Oct25
2.83
305
SUSP_OBFUS_JS_FromCharCode_PlainChain_Jul26
2.97
109
SUSP_Screen_Capture_Indicators_Sep26
3.0
14
SUSP_JS_Executable_Downloader_Jan26
3.07
14
SUSP_JAVA_EXPL_Payloads_Oct25
3.16
63
SUSP_Claude_Refusal_Magic_String_Jan26
3.24
29
EXPL_SUSP_JS_POC_Dec25
3.46
35
SUSP_ELF_EXPL_Indicators_May26
3.6
410
EXPL_RCE_React_Server_CVE_2025_55182_POC_Dec25
3.67
15
SUSP_PS1_HistorySaveStyle_SaveNothing_Oct25
4.18
11
PUA_Windows_TOR_Client_Jun26
5.25
48

Latest YARA Matches with Low AV Detection Rate

This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)

Rule
AVs
Hash
VT
Webshell_like_System_Shell_Exec
4
7a90a3df82cf88cd9c8c833757c6f9c9d7b7713f64014f6a94e2eb1c6118849f
SUSP_ELF_EXPL_Indicators_May26
4
7a90a3df82cf88cd9c8c833757c6f9c9d7b7713f64014f6a94e2eb1c6118849f
WEBSHELL_PHP_Generic_Eval
4
7a90a3df82cf88cd9c8c833757c6f9c9d7b7713f64014f6a94e2eb1c6118849f
PUA_ConnectWise_ScreenConnect_Mar23
11
7a62313295cc6d259eafd6c9d2478ebf9efc9f2dc4c6db88ead27ca85f6f6afa
SUSP_PY_Exploit_Code_Oct25
4
7a90a3df82cf88cd9c8c833757c6f9c9d7b7713f64014f6a94e2eb1c6118849f
SUSP_PS1_Casing_Anomaly_Compression_Apr25
2
56b4dc785b335ef4c61f1fbef3a1ab606198382f1ba529a6313cd442561ccf42
SUSP_B64_Atob_Aug23
6
17639135ebc36b96b01a9b8da7f53ae2c8779e2fc392015fc1abf8f1b1571264
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
6
17639135ebc36b96b01a9b8da7f53ae2c8779e2fc392015fc1abf8f1b1571264
Casing_Anomaly_PS_Convert
2
56b4dc785b335ef4c61f1fbef3a1ab606198382f1ba529a6313cd442561ccf42
SUSP_PS1_Small_Base64Decode_Jun22_1
2
56b4dc785b335ef4c61f1fbef3a1ab606198382f1ba529a6313cd442561ccf42
Casing_Anomaly_IO_MemoryStream
2
56b4dc785b335ef4c61f1fbef3a1ab606198382f1ba529a6313cd442561ccf42
SUSP_Base64_Encoded_Hex_Encoded_Code
6
17639135ebc36b96b01a9b8da7f53ae2c8779e2fc392015fc1abf8f1b1571264
SUSP_Go_Malware_Indicators_Nov25
4
c57c2c3a748e750b931f963a795b4b26eb4724914324aaaffe9860c2efe1ac92
SUSP_B64_Atob_Aug23
12
5ae8eb94f8322068d429d9fbb771f8cc6769371955782bef3984d09850ac3617
SUSP_PE_Themida_Packed_Nov22
6
1b0688b40ba95e1f7c7f3aaa7bfc3376e006a13cd326d7beba1107720f5cebdb
SUSP_IndexOf_Obfuscation_JScript_Feb20_1
10
c91f822b0d408003902f6ffe0dc93c8d94494afc49db604f14969943c3e6592b
SUSP_Base64_Encoded_Hex_Encoded_Code
8
8b0844c622cc001aafa0cbd56308586e160704b02276820f61a817becfd5e5c4
SUSP_B64_Atob_Aug23
8
8b0844c622cc001aafa0cbd56308586e160704b02276820f61a817becfd5e5c4
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
8
8b0844c622cc001aafa0cbd56308586e160704b02276820f61a817becfd5e5c4
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
13
0ae78e2339f8bba6a1b6668b994d32476c6f79b247d0ea465499c7aaefc1b05c

YARA Rules Per Category

This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)

Tag
Count
Malware
7904
Threat Hunting (not subscribable, only in THOR scanner)
6078
APT
5104
Hacktools
4916
Webshells
2406
Exploits
751

Newest Sigma Rules

This table shows the newest additions to the Sigma rule set

Rule
Description
Date
Ref
Info
Potentially Suspicious Image Load of Tlscsp.dll
Detects tlscsp.dll ("Microsoft Remote Desktop Services Cryptographic Utility") loaded by a process outside standard Microsoft or system directories. The DLL contains a hardcoded RC4 key exposed through its LsCsp_EncryptHwid export, providing a predictable cryptographic primitive that malware can leverage to decrypt payloads or encrypt data without embedding custom crypto code. Loading this DLL from an unexpected location is potentially suspicious, as threat actors abuse a trusted system component to perform cryptographic operations natively, bypassing detection that would otherwise flag unsigned or anomalous crypto implementations.
24.09.2026
Potential PowerShell Keylogger via Low-Level Keyboard Hook
Detects PowerShell ScriptBlock containing inline C# that installs a low-level keyboard hook via SetWindowsHookEx with the WH_KEYBOARD_LL hook type. Attackers use Add-Type to compile and execute a keylogger entirely in memory, intercepting all keystrokes system-wide without dropping a standalone binary to disk. The presence of CallNextHookEx confirms a chained hook implementation, distinguishing it from benign API references.
16.09.2026
Potential PowerShell Screen Capture via Win32 GDI BitBlt
Detects PowerShell ScriptBlock using the Win32 GDI BitBlt API to capture screen content. Attackers use this native approach to silently copy display pixel data without dropping a standalone capture binary, a technique commonly observed in keyloggers, RATs and spyware.
16.09.2026
PowerShell Script Execution From Environment Variable - ScriptBlock
Detects PowerShell loading and executing a script stored inside an environment variable. Attackers use this to hide the malicious code from command-line logs and security tools, since the actual script is never written to disk or shown in the process arguments.
08.09.2026
PowerShell Script Execution From Environment Variable - CommandLine
Detects PowerShell loading and executing a script stored inside an environment variable. Attackers use this to hide the malicious code from command-line logs and security tools, since the actual script is never written to disk or shown in the process arguments.
08.09.2026
Kernel Driver Service ImagePath Set by Potentially Suspicious Process
Detects kernel driver service ImagePath registry values being set by potentially suspicious processes. This can indicate attempts to load kernel drivers without using the standard Service Control Manager, which malware may use to maintain persistence or employ BYOVD techniques often used in EDR killer tools. It's recommended to first baseline this rule in your environment and adjust it accordingly before enabling it in production.
02.09.2026
Kernel Driver Service ImagePath Pointing to Non-Standard Location
Detects kernel driver service ImagePath registry values that point to non-standard locations outside typical Windows driver directories. This may indicate attempts to load malicious or vulnerable kernel drivers for persistence or privilege escalation, a technique commonly observed in EDR-killer tools that drop a driver to a non-standard location before loading it for further exploitation. It's recommended to first baseline this rule in your environment and adjust it accordingly before enabling it in production.
02.09.2026
PUA - Tailcat Saved Key Generation - Linux
Detects the generation of Tailcat saved keys that persist the secret between multiple sessions. Using Tailcat persistently is unusual in corporate environments.
02.09.2026
PUA - Tailcat Saved Key Generation - Windows
Detects the generation of Tailcat saved keys that persist the secret between multiple sessions. Using Tailcat persistently is unusual in corporate environments.
02.09.2026
Remote PDF Opened via Explorer with HTTP URL
Detects explorer.exe being invoked with an HTTP URL pointing to a remote PDF file. Attackers use this technique to display a decoy document while a malicious payload executes in the background, distracting the victim after LNK-based initial access. explorer.exe is not normally launched from the command line with a remote HTTP path; its appearance in such a context is a strong indicator of a scripted attack chain.
31.08.2026
EventLog Metadata Inspection Via Wevtutil
Detects the eventlog metadata inspection attempt via wevtutil.exe. Threat actors use these to verify whether security logging is active and gauge how much time they have before entries are overwritten, before performing intrusive actions.
27.08.2026
Email Protocol Access Via Curl
Detects curl.exe being used to access email servers over IMAP or SMTP protocols. Curl natively supports IMAP/IMAPS and SMTP/SMTPS, allowing attackers to interact with mailboxes directly from the command line - reading inbox contents, selecting folders, or sending messages - without deploying a dedicated mail client. This technique is used for C2 communication via corporate mail infrastructure and for data exfiltration, blending with legitimate email traffic.
27.08.2026
Renamed Node.js Binary Execution
Detects the execution of a renamed Node.js JavaScript runtime, normally named "node.exe". Node.exe is the executable file for the Node.js JavaScript runtime and is typically used to execute JavaScript code outside a web browser environment. Threat actors may rename the Node.js executable to a random name to run malicious scripts stealthily.
26.08.2026
Senstitive File Access via Cmd Utility
Detects the usage of windows inbuilt cmd.exe utility to access sensitive files such as configuration files, certificate files, and password files. It might indicate an adversary attempting to access sensitive files for credential access or collection purposes via reverse shell or cli interaction.
26.08.2026
SSH Known Hosts File Deleted
Detects deletion of SSH known_hosts files via file deletion events. Complements the proc_creation variant by catching cases where the shell handles the operation directly (e.g. bare redirects, unlink syscalls) without spawning a traceable child process. Attackers remove known_hosts to erase lateral movement destinations and suppress SSH host key mismatch warnings.
19.08.2026
Linux Log File Content Cleared or Deleted via CLI Utilities
Detects unusual CLI-based methods to clear or delete Linux log file contents, including truncating to zero size, overwriting with /dev/null, and other methods. These techniques are commonly used by attackers and ransomware to destroy forensic evidence before or after malicious activity.
19.08.2026
Logging Daemon Force Killed via CommandLine
Detects use of kill, killall, pkill, or other command line methods to forcefully terminate common Linux logging and auditing services. Threat actors or malware may use this technique to silence audit trails before encryption or exfiltration.
19.08.2026
SSH Known Hosts File Removed or Cleared
Detects removal or clearing of SSH known_hosts files via common CLI utilities. Attackers delete known_hosts to erase evidence of lateral movement destinations and to suppress SSH host key mismatch warnings when reconnecting to a host whose key has been changed.
19.08.2026
Logging Service Stopped or Disabled via Systemctl
Detects use of systemctl to stop, kill, mask, or disable common Linux logging and auditing services (rsyslog, syslog-ng, auditd, systemd-journald). Attackers and ransomware use this to silence audit trails before encryption or exfiltration. Masking a service additionally prevents it from being restarted by other processes.
19.08.2026
Logging Service Stopped via Service Command
Detects use of the legacy service command to stop common Linux logging and auditing services. The service command wraps SysV init scripts and remains functional on systemd-based distributions via compatibility shims. Attackers use this to stop logging with a command that blends into older administration patterns.
19.08.2026
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
19.08.2026
New User Account Creation Attempt Via ADSI
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using either the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
New User Account Creation Attempt Via ADSI in CommandLine
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
PowerShell Live Kernel Dump
Detects PowerShell scripts or commands that create live kernel dumps. While live kernel dumps are a legitimate diagnostic mechanism, they are increasingly abused by threat actors to read sensitive process memory such as LSASS without opening a direct process handle, bypassing traditional process-access based detections.
10.08.2026
Live Kernel Dump via CommandLine
Detects live kernel dumps initiated via the command line. While kernel dumps are not inherently malicious, these dumps can be accessed to read sensitive process memory such as LSASS without opening a direct process handle, bypassing traditional process-access based detections.
10.08.2026
Potential Crontab Persistence via CLI
Detects command lines attempting to install a crontab persistence via cli by echoing a cron schedule and piping it to 'crontab -' via stdin. Attackers may use this technique to establish persistence on a compromised system by scheduling malicious tasks to run at regular intervals.
07.08.2026
Container Overlay Filesystem Enumeration via Mount - Linux
Detects processes enumerating overlay filesystems by piping mount output through grep for "overlay". This technique is used by attackers to detect if they are running inside a container (e.g., Docker, Podman), which is a common precursor to container escape attempts or environment-aware malware behaviour.
07.08.2026
Suspicious Grep of Sensitive Contents for Credential Access
Detects the use of grep to search for sensitive credentials and cryptocurrency wallet mnemonics. This behaviour may indicate an adversary trying to to locate sensitive credentials contained in environment variable files, private keys, certificates, wallet files, or other files that may contain secrets which could be used for credential access or further compromise.
07.08.2026
Sensitive File Discovery via Find Command
Detects aggressive filesystem searches for credential, certificate, and wallet files using the 'find' command. This behavior may indicate an adversary attempting to locate sensitive files such as environment variable files, private keys, certificates, or wallet files that could be used for credential access or further compromise.
07.08.2026
PostgreSQL Connection String Enumeration via Grep
Detects the use of grep to search for PostgreSQL connection strings and database URLs, which may indicate credential harvesting from application directories as a precursor to lateral movement or data exfiltration. Attackers may use this technique to find hardcoded database credentials in source code, configuration files, or environment variable definitions.
07.08.2026

YARA/SIGMA Rule Count

Rule Type
Community Feed
Nextron Private Feed
Yara
1298
23341
Sigma
3617
1107

Sigma Rules Per Category (Community)

Type
Count
windows / process_creation
1359
windows / registry_set
219
windows / file_event
211
windows / ps_script
167
windows / security
164
linux / process_creation
142
windows / image_load
115
webserver
86
windows / system
74
macos / process_creation
69
aws / cloudtrail
57
proxy
55
linux / auditd
54
windows / network_connection
53
azure / auditlogs
44
windows / registry_event
40
azure / activitylogs
35
windows / ps_module
33
windows / application
32
windows / dns_query
28
windows / process_access
25
opencanary / application
24
okta / okta
22
windows / pipe_created
19
azure / riskdetection
19
azure / signinlogs
18
rpc_firewall / application
17
windows / windefend
17
gcp / gcp.audit
16
linux / file_event
16
linux
16
github / audit
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / driver_load
10
antivirus
9
windows / ps_classic_start
9
windows / create_stream_hash
9
windows / appxdeployment-server
9
windows / firewall-as
8
windows / msexchange-management
8
windows / bits-client
7
gcp / google_workspace.admin
7
zeek / smb_files
7
fortigate / event
7
windows / file_access
7
azure / pim
7
windows / dns-client
6
kubernetes / audit
6
zeek / dns
5
linux / network_connection
5
zeek / http
5
jvm / application
5
zeek / dce_rpc
4
m365 / audit
4
windows / sysmon
4
macos / file_event
4
windows / taskscheduler
4
windows / iis-configuration
4
linux / sshd
3
windows / registry_add
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
windows / ntlm
3
linux / syslog
2
windows / security-mitigations
2
spring / application
2
windows / dns-server
2
apache
2
windows / wmi
2
onelogin / onelogin.events
2
windows / applocker
2
firewall
2
windows / file_change
1
windows / smbclient-connectivity
1
windows / smbserver-connectivity
1
nodejs / application
1
paloalto / file_event / globalprotect
1
zeek / x509
1
windows / capi2
1
windows / shell-core
1
windows / raw_access_thread
1
paloalto / appliance / globalprotect
1
windows / certificateservicesclient-lifecycle-system
1
windows / file_executable_detected
1
python / application
1
linux / vsftpd
1
windows / microsoft-servicebus-client
1
windows / file_rename
1
windows / diagnosis-scripted
1
windows / smbclient-security
1
windows / sysmon_error
1
m365 / exchange
1
zeek / rdp
1
ruby_on_rails / application
1
zeek / kerberos
1
windows / terminalservices-localsessionmanager
1
windows / sysmon_status
1
m365 / threat_detection
1
windows / driver-framework
1
windows
1
sql / application
1
linux / sudo
1
velocity / application
1
cisco / duo
1
cisco / ldp
1
nginx
1
windows / dns-server-analytic
1
cisco / bgp
1
windows / ps_classic_provider_start
1
windows / printservice-operational
1
database
1
windows / lsa-server
1
django / application
1
windows / printservice-admin
1
linux / clamav
1
windows / ldap
1
linux / auth
1
linux / guacamole
1
fortios / sslvpnd
1
linux / cron
1
juniper / bgp
1
windows / appmodel-runtime
1
windows / openssh
1
windows / process_tampering
1
cisco / syslog
1
huawei / bgp
1
windows / appxpackaging-om
1

Sigma Rules Per Category (Nextron Private Feed)

Type
Count
windows / process_creation
544
windows / registry_set
97
windows / ps_script
95
linux / process_creation
72
windows / file_event
52
windows / image_load
49
windows / wmi
29
windows / security
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ps_module
5
windows / dns_query
5
windows / ntfs
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / registry_delete
4
windows / create_remote_thread
4
windows / ps_classic_script
3
windows / vhd
3
windows / application-experience
3
windows / hyper-v-worker
3
windows / driver_load
3
macos / process_creation
3
dns
3
windows / environment variable / THOR
2
linux / Linux kernel module / THOR
2
windows / smbclient-security
2
windows / process_access
2
windows / windefend
2
windows / bits-client
2
windows / codeintegrity-operational
2
linux / file_delete
2
windows / file_delete
2
linux / file_event
2
windows / kernel-shimengine
2
windows / file_access
2
windows / application
1
linux / Unix user / THOR
1
windows / audit-cve
1
windows / amsi
1
windows / registry-setinformation
1
windows / firewall-as
1
windows / file_rename
1

Tenable Nessus

Requirement: Privileged Scan

  • YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
Tutorial: https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

YARA Scanning with Nessus

  • You can only upload a single .yar file
  • Filesystem scan has to be activated
  • You have to define the target locations
  • The Nessus plugin ID will be 91990
  • Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
Tutorial: https://de.tenable.com/blog/threat-hunting-with-yara-and-nessus

Carbon Black

Tutorial: https://github.com/carbonblack/cb-yara-connector

FireEye EX

Tutorial: https://www.fireeye.com/blog/products-and-services/2018/12/detect-and-block-email-threats-with-custom-yara-rules.html