Valhalla Logo
currently serving 24585 YARA rules and 4718 Sigma rules
API Key

New Rules per Day

Newest YARA Rules

This table shows the newest additions to the YARA rule set

Rule
Description
Date
Ref
HKTL_MSNightmare_ShieldCrash_Sep26
Detects ShieldCrash a new iteration of the Microsoft Defender exploit ShieldBreak. The hacktool is used to bypass Windows Defender and execute arbitrary code on the system.
09.09.2026
SUSP_UEFI_Embedded_EXE_Sep26
Detects UEFI binaries that has Embedded Windows executables, which may indicate a potential injection of Windows code from the UEFI environment
09.09.2026
SUSP_UEFI_Characteristics_Sep26
Detects UEFI binaries suspicious characteristics such as Windows functions, disabling SMEP and WP, or containing a PE loader, which may indicate attempts to load or inject Windows code from the UEFI environment and bypass security mechanisms. Further analysis is advised
09.09.2026
MAL_UEFI_XigMapper_Bootkit_Sep26
Detects Xigmapper UEFI bootkit that installs hooks into ntoskrnl.exe to load malicious kernel modules
08.09.2026
HKTL_MSNightmare_FalconFlank_Sep26
Detects FalconFlank hacktool used for privilege escalation on Windows through CrowdStrike Falcon.
03.09.2026
MAL_MILDFROST_DNS_Tunneler_Sep26
Detects MildFrost DNS Tunneler, a tool that establishes a DNS tunnel for data exfiltration and command-and-control communication
03.09.2026
MAL_BOATBEAM_Backdoor_Sep26
Detects BOATBEAM, a Golang backdoor masquerading as an IIS HTTPS server to conceal C2 traffic.
03.09.2026
MAL_KICKPLATE_Backdoor_Sep26
Detects KICKPLATE, a backdoor that impersonates Windows Update Health Tools and uses multiple techniques for persistence.
03.09.2026
SUSP_VBS_Hide_Zip_Archive_Extraction_Sep26
Detects suspicious VBS scripts that hide ZIP archive extraction, commonly used by malware to conceal payload delivery
02.09.2026
MAL_COBALTSPIN_Reverse_Proxy_Sep26
Detects CobaltSpin Reverse Proxy Client, a tool that establishes a reverse SOCKS5 proxy connection to a remote server
02.09.2026
MAL_REALBREEZE_LDAP_Brute_Forcing_Utility_Sep26
Detects RealBreeze LDAP Brute Forcing Utility, a tool used to perform brute force attacks on LDAP servers
02.09.2026
PUA_Tailcat_Sep26
Detects Tailcat executables and library usage. Tailcat is a tool like netcat, but over Tailscale's data plane, without Tailscale's control plane. Has SSH server, SOCKS5 proxy and file transfer capabilities.
01.09.2026
HKTL_HackBrowserData_Sep26
Detects HackBrowserData, a tool used to extract credentials from browsers
01.09.2026
MAL_LNX_SSHHijack_Sep26
Detects Linux binaries that attempt to hijack SSH sessions and steal credentials
01.09.2026
MAL_LNX_CS_Beacon_Sep26
Detects Cobalt Strike beacon for Linux. Cobalt Strike is a commercial C2 framework used by redteams and abused by threat actors. Its features include covert data exfiltration and persistent remote access among others.
01.09.2026
HKTL_PrettyPrague_Sep26
Detects PrettyPrague hacktool used for LPE (Local-Privilege-Escalation) and credential dumping. The tool exploits the sandbox component of Avast to gain system permissions and dump LSA credentials.
01.09.2026
HKTL_NightmareEclipse_Indicators_Sep26
Detects specific code used in hacktools written by NightmareEclipse (MSNightmare). Tooling includes Windows Defender exploits and Local-Privilege-Escalation.
01.09.2026
HKTL_KeyTheft_Aug26
Detects KeyTheft, a hacktool to dump the SAM via RemoteRegistry handle
31.08.2026
SUSP_PNG_Additional_Data_Aug26
Detects 1x1 pixel PNG files which contain additional data e.g. the output of the KeyTheft hacktool
31.08.2026
APT_Virtualizor_Compromise_ForensicArtifacts_Aug26
Detects forensic artifacts found in a campaign against compromised hosting providers using Virtualizor software
31.08.2026
APT_Virtualizor_Compromise_Payload_Aug26
Detects java based payload used in a campaign against compromised hosting providers using Virtualizor software
31.08.2026
SUSP_PY_Object_Graph_Traversal_Aug26
Detects Python code traversing the object graph to locate Python functions which may be detected by security products or hidden by sandbox engines
31.08.2026
SUSP_PY_Import_Encoding_Aug26
Detects suspicious encodings of Python's import keyword
31.08.2026
SUSP_JS_XOR_Dropper_Aug26
Detects suspicious XOR-decoding in JavaScript code seen being used to execute further malicious payload
31.08.2026
SUSP_JS_XOR_Dropper_Aug26_2
Detects suspicious XOR-decoding in JavaScript code seen being used to execute further malicious payload
31.08.2026
MAL_Loader_Aug26
Detects a loader being used to load AcrStealer and other malware
31.08.2026
MAL_APT_UAC0099_LunchPoke_Loader_Aug26
Detects LunchPoke, a loader used by UAC-0099 APT to drop BurnyBear Downloader
31.08.2026
MAL_APT_UAC0099_BurnyBear_Downloader_Aug26
Detects BurnyBear, a downloader used by UAC-0099 APT to download and execute other malwares
31.08.2026
SUSP_VBS_Downloader_Aug26
Detects suspicious VBS scripts used to download and execute other payloads
30.08.2026
MAL_APT_UAC0099_MatchBoil_Backdoor_Aug26
Detects MatchBoil, a backdoor used by UAC-0099 APT to execute commands and load other payloads
30.08.2026

Successful YARA Rules in Set

This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)

Rule
Average AV Detection Rate
Sample Count
Info
VT
MAL_JS_AI_Exfiltration_Dec25
0.0
11
HKTL_Kali_Liunx_Virtual_Machine_Jan26
0.0
11
PUA_NinjaOne_RMM_Jan26
0.0
22
SUSP_JS_XMLHttpRequest_Overwrite_Dec25
0.0
174
SUSP_JS_WebSocket_Overwrite_Dec25
0.0
82
SUSP_EXPL_Filename_Indicators_Dec25
0.18
196
SUSP_OBFUSC_JS_Patterns_Apr26
0.33
36
SUSP_VBS_Tiny_Indicators_Sep25
0.64
14
MAL_Rootkit_Characteristic_Jan26
0.74
19
MAL_LNX_SSHHijack_Sep26
0.75
20
MAL_Implant_Indicators_Jul26
1.18
51
SUSP_BAT_Persistence_Oct25
1.67
12
SUSP_Exploit_Indicators_Oct25
1.91
195
SUSP_PS1_OBFUSC_Patterns_Nov25_1
2.03
121
PUA_Tailcat_Sep26
2.11
27
SUSP_Unsigned_RuskDesk_Remote_Desktop_Nov25
2.38
16
SUSP_Go_Binary_Ngrok_Tunnel_Indicators_Oct25
2.54
24
SUSP_LNK_WScript_Execution_May26
2.75
36
SUSP_Go_LibP2P_Library_Aug26
3.0
15
SUSP_PS1_HistorySaveStyle_SaveNothing_Oct25
3.31
16
SUSP_Certutil_Encode_Decode_Hex_May26
5.12
17
MAL_Overlord_RAT_Apr26
5.2
49
SUSP_PY_Exploit_Code_Oct25
5.21
154
SUSP_OBFUS_JS_FromCharCode_Encoding_Jul26
5.69
77
SUSP_PY_Function_Names_Oct25
5.71
226
MAL_Ethar_Rat_Jul26
6.44
32
PUA_Syncro_RMM_Jan26
6.47
19
SUSP_PE_Embedded_In_Image_File_Oct25
6.57
14
SUSP_PY_Suspicious_Functions_Oct25
6.78
237
SUSP_VBS_Hide_Zip_Archive_Extraction_Sep26
6.93
14

Latest YARA Matches with Low AV Detection Rate

This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)

Rule
AVs
Hash
VT
SUSP_Base64_Encoded_Hex_Encoded_Code
8
fd8be611ee96ae65e447fc4444dbc543fb30e372c50184c122be831641f1772b
SUSP_Base64_Encoded_Hex_Encoded_Code
6
64d7e4c9e710aa3cfe5e9a7b2805c318b43da44feca3a710bf78f77e0d8ce429
MAL_Sednit_DelphiDownloader_Apr18_2
1
e34c4787f21527a45676db9b530f63295380c18b516335939e149d21543abfc2
SUSP_Base64_Encoded_Hex_Encoded_Code
8
e9662804020a1fc7bdb51f27755a3802c9859ef7b213b9716d89d09018e054e1
SUSP_Base64_Encoded_Hex_Encoded_Code
7
30ea848deb72642220e58e84f958711cc899ef8f529f31ce70475c37525b1a4b
SUSP_Base64_Encoded_Hex_Encoded_Code
8
a2e6aa34e71675462d3a2f46fd6aa5cc560b250d92f7c14702b75415fbe461a8
SUSP_Base64_Encoded_Hex_Encoded_Code
5
df5cde3c320902349f688dcf33f0b54c891567408d542a5576eabd8841cfb6eb
MAL_Sednit_DelphiDownloader_Apr18_2
1
590aed85a8af78b30a174216a074b3e5c57275d91f39735ecef32e7aad57c852
SUSP_Base64_Encoded_Hex_Encoded_Code
5
6e35774b42eef0dd97355dec8988e14073c014c1344857c6917f431974cd82ba
SUSP_Base64_Encoded_Hex_Encoded_Code
8
eed85fd30b18626d467b2fb6d3bbd2717a28e65d57378ad9d4b699978553e7c6
SUSP_Base64_Encoded_Hex_Encoded_Code
8
94869560b41d367e86d04a7b4fc1d46a3042645403ff1345b2da5c352115a935
SUSP_PE_Sections_May25
9
f36a37276ac0ce275cd31cb6175641870c40a19e8c93f3dc9ceff3a1395e7973
SUSP_Base64_Encoded_Hex_Encoded_Code
8
9167bbfb7cf1ac8be03be1a950d3db31c08a51d412dfbc28be35b74131c33977
SUSP_ELF_EXPL_Indicators_May26
1
95cda44ade025c1567d3e5dee4d9c0a427a0a1b576bc9b9e2874e1e1c7a844ce
SUSP_Base64_Encoded_Hex_Encoded_Code
8
058536e340af2c09b97fed920b0c595428c908b943ab5ed2bfb7efdd1cc1ac8e
MAL_Sednit_DelphiDownloader_Apr18_2
2
72f8177aea997315ab86a6b5c274ae9d2a0df778b1893b9a2a64d4077dac971f
MAL_LNX_Mirai_Watchdog_Jun25
14
aec420febc0fbf8eeed87c98dbb2530cfcb9ebadbd356ada656623effb7bdbae
MAL_LNX_Mirai_Watchdog_Jun25
13
3b7565d13e1647aae20e766f434cedfb4a7870d73be4f74f11e8dc1a5a7cba12
MAL_LNX_Mirai_Watchdog_Jun25
13
b4fe6753dfc15622c26798cd5a33cdaa80d0c20702d5ebfd1ada15f01a9aaed5
SUSP_Base64_Encoded_Hex_Encoded_Code
8
257f152242d039b0ed73d84e4d51a4465cc12df71425ab7c6313231f128ac9c6

YARA Rules Per Category

This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)

Tag
Count
Malware
7877
Threat Hunting (not subscribable, only in THOR scanner)
6054
APT
5097
Hacktools
4915
Webshells
2405
Exploits
749

Newest Sigma Rules

This table shows the newest additions to the Sigma rule set

Rule
Description
Date
Ref
Info
Kernel Driver Service ImagePath Set by Potentially Suspicious Process
Detects kernel driver service ImagePath registry values being set by potentially suspicious processes. This can indicate attempts to load kernel drivers without using the standard Service Control Manager, which malware may use to maintain persistence or employ BYOVD techniques often used in EDR killer tools. It's recommended to first baseline this rule in your environment and adjust it accordingly before enabling it in production.
02.09.2026
Kernel Driver Service ImagePath Pointing to Non-Standard Location
Detects kernel driver service ImagePath registry values that point to non-standard locations outside typical Windows driver directories. This may indicate attempts to load malicious or vulnerable kernel drivers for persistence or privilege escalation, a technique commonly observed in EDR-killer tools that drop a driver to a non-standard location before loading it for further exploitation. It's recommended to first baseline this rule in your environment and adjust it accordingly before enabling it in production.
02.09.2026
PUA - Tailcat Saved Key Generation - Linux
Detects the generation of Tailcat saved keys that persist the secret between multiple sessions. Using Tailcat persistently is unusual in corporate environments.
02.09.2026
PUA - Tailcat Saved Key Generation - Windows
Detects the generation of Tailcat saved keys that persist the secret between multiple sessions. Using Tailcat persistently is unusual in corporate environments.
02.09.2026
Remote PDF Opened via Explorer with HTTP URL
Detects explorer.exe being invoked with an HTTP URL pointing to a remote PDF file. Attackers use this technique to display a decoy document while a malicious payload executes in the background, distracting the victim after LNK-based initial access. explorer.exe is not normally launched from the command line with a remote HTTP path; its appearance in such a context is a strong indicator of a scripted attack chain.
31.08.2026
EventLog Metadata Inspection Via Wevtutil
Detects the eventlog metadata inspection attempt via wevtutil.exe. Threat actors use these to verify whether security logging is active and gauge how much time they have before entries are overwritten, before performing intrusive actions.
27.08.2026
Email Protocol Access Via Curl
Detects curl.exe being used to access email servers over IMAP or SMTP protocols. Curl natively supports IMAP/IMAPS and SMTP/SMTPS, allowing attackers to interact with mailboxes directly from the command line - reading inbox contents, selecting folders, or sending messages - without deploying a dedicated mail client. This technique is used for C2 communication via corporate mail infrastructure and for data exfiltration, blending with legitimate email traffic.
27.08.2026
Renamed Node.js Binary Execution
Detects the execution of a renamed Node.js JavaScript runtime, normally named "node.exe". Node.exe is the executable file for the Node.js JavaScript runtime and is typically used to execute JavaScript code outside a web browser environment. Threat actors may rename the Node.js executable to a random name to run malicious scripts stealthily.
26.08.2026
Senstitive File Access via Cmd Utility
Detects the usage of windows inbuilt cmd.exe utility to access sensitive files such as configuration files, certificate files, and password files. It might indicate an adversary attempting to access sensitive files for credential access or collection purposes via reverse shell or cli interaction.
26.08.2026
SSH Known Hosts File Deleted
Detects deletion of SSH known_hosts files via file deletion events. Complements the proc_creation variant by catching cases where the shell handles the operation directly (e.g. bare redirects, unlink syscalls) without spawning a traceable child process. Attackers remove known_hosts to erase lateral movement destinations and suppress SSH host key mismatch warnings.
19.08.2026
Logging Daemon Force Killed via CommandLine
Detects use of kill, killall, pkill, or other command line methods to forcefully terminate common Linux logging and auditing services. Threat actors or malware may use this technique to silence audit trails before encryption or exfiltration.
19.08.2026
Linux Log File Content Cleared or Deleted via CLI Utilities
Detects unusual CLI-based methods to clear or delete Linux log file contents, including truncating to zero size, overwriting with /dev/null, and other methods. These techniques are commonly used by attackers and ransomware to destroy forensic evidence before or after malicious activity.
19.08.2026
Logging Service Stopped via Service Command
Detects use of the legacy service command to stop common Linux logging and auditing services. The service command wraps SysV init scripts and remains functional on systemd-based distributions via compatibility shims. Attackers use this to stop logging with a command that blends into older administration patterns.
19.08.2026
SSH Known Hosts File Removed or Cleared
Detects removal or clearing of SSH known_hosts files via common CLI utilities. Attackers delete known_hosts to erase evidence of lateral movement destinations and to suppress SSH host key mismatch warnings when reconnecting to a host whose key has been changed.
19.08.2026
Logging Service Stopped or Disabled via Systemctl
Detects use of systemctl to stop, kill, mask, or disable common Linux logging and auditing services (rsyslog, syslog-ng, auditd, systemd-journald). Attackers and ransomware use this to silence audit trails before encryption or exfiltration. Masking a service additionally prevents it from being restarted by other processes.
19.08.2026
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
19.08.2026
New User Account Creation Attempt Via ADSI
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using either the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
New User Account Creation Attempt Via ADSI in CommandLine
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
PowerShell Live Kernel Dump
Detects PowerShell scripts or commands that create live kernel dumps. While live kernel dumps are a legitimate diagnostic mechanism, they are increasingly abused by threat actors to read sensitive process memory such as LSASS without opening a direct process handle, bypassing traditional process-access based detections.
10.08.2026
Live Kernel Dump via CommandLine
Detects live kernel dumps initiated via the command line. While kernel dumps are not inherently malicious, these dumps can be accessed to read sensitive process memory such as LSASS without opening a direct process handle, bypassing traditional process-access based detections.
10.08.2026
Potential Crontab Persistence via CLI
Detects command lines attempting to install a crontab persistence via cli by echoing a cron schedule and piping it to 'crontab -' via stdin. Attackers may use this technique to establish persistence on a compromised system by scheduling malicious tasks to run at regular intervals.
07.08.2026
Container Overlay Filesystem Enumeration via Mount - Linux
Detects processes enumerating overlay filesystems by piping mount output through grep for "overlay". This technique is used by attackers to detect if they are running inside a container (e.g., Docker, Podman), which is a common precursor to container escape attempts or environment-aware malware behaviour.
07.08.2026
Sensitive File Discovery via Find Command
Detects aggressive filesystem searches for credential, certificate, and wallet files using the 'find' command. This behavior may indicate an adversary attempting to locate sensitive files such as environment variable files, private keys, certificates, or wallet files that could be used for credential access or further compromise.
07.08.2026
PostgreSQL Connection String Enumeration via Grep
Detects the use of grep to search for PostgreSQL connection strings and database URLs, which may indicate credential harvesting from application directories as a precursor to lateral movement or data exfiltration. Attackers may use this technique to find hardcoded database credentials in source code, configuration files, or environment variable definitions.
07.08.2026
Suspicious Grep of Sensitive Contents for Credential Access
Detects the use of grep to search for sensitive credentials and cryptocurrency wallet mnemonics. This behaviour may indicate an adversary trying to to locate sensitive credentials contained in environment variable files, private keys, certificates, wallet files, or other files that may contain secrets which could be used for credential access or further compromise.
07.08.2026
Suspicious Node.js Child Process with IP Address - Linux
Detects a Node.js process spawning a shell or network utility with a command line containing an IPv4 address. This pattern is commonly used by malicious npm postinstall scripts to download second-stage payloads or establish reverse shells, as observed in various malicious Strapi npm campaign.
07.08.2026
Node.Js Inline Script Network Connection - Linux
Detects inline Node.js scripts that establish network connections, which may indicate malicious activity such as data exfiltration or command-and-control communication. Attackers may use inline Node.js scripts to quickly execute code that interacts with the network without leaving a persistent file on disk.
07.08.2026
Node.Js Inline Script Network Connection
Detects inline Node.js scripts that establish network connections, which may indicate malicious activity such as data exfiltration or command-and-control communication. Attackers may use inline Node.js scripts to quickly execute code that interacts with the network without leaving a persistent file on disk.
07.08.2026
Suspicious Node.js Child Process with IPv4 Address
Detects a Node.js child process command line containing an IPv4 address. This might indicate a malicious npm postinstall script downloading second-stage payloads or establishing reverse shells, as observed in various malicious npm campaigns or supply chain attacks.
07.08.2026
ADCS - Certighost Ghost Machine Account Creation
Detects the creation of a machine account whose name starts with 'GHOST', which is the naming convention used by the CVE-2026-54121 (Certighost) exploit tooling. The public proof-of-concept for Certighost creates a temporary machine account with a name of the form GHOST<random>$ before enrolling for a DC certificate via the cdc chase path. The attacker-controlled machine account is used as the requester identity in the certificate request; the cdc attribute then redirects the CA to a rogue host that returns a forged Domain Controller identity. The resulting certificate carries the DC's SID and DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync. A machine account creation event (4741) where TargetUserName starts with 'GHOST' and ends with '$' is a high-fidelity indicator of this attack tool's execution. Legitimate environments very rarely provision machine accounts with this prefix.
30.07.2026

YARA/SIGMA Rule Count

Rule Type
Community Feed
Nextron Private Feed
Yara
1298
23287
Sigma
3617
1101

Sigma Rules Per Category (Community)

Type
Count
windows / process_creation
1359
windows / registry_set
219
windows / file_event
211
windows / ps_script
167
windows / security
164
linux / process_creation
142
windows / image_load
115
webserver
86
windows / system
74
macos / process_creation
69
aws / cloudtrail
57
proxy
55
linux / auditd
54
windows / network_connection
53
azure / auditlogs
44
windows / registry_event
40
azure / activitylogs
35
windows / ps_module
33
windows / application
32
windows / dns_query
28
windows / process_access
25
opencanary / application
24
okta / okta
22
azure / riskdetection
19
windows / pipe_created
19
azure / signinlogs
18
rpc_firewall / application
17
windows / windefend
17
linux
16
linux / file_event
16
gcp / gcp.audit
16
github / audit
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / appxdeployment-server
9
antivirus
9
windows / ps_classic_start
9
windows / create_stream_hash
9
windows / firewall-as
8
windows / msexchange-management
8
azure / pim
7
windows / file_access
7
windows / bits-client
7
gcp / google_workspace.admin
7
zeek / smb_files
7
fortigate / event
7
kubernetes / audit
6
windows / dns-client
6
jvm / application
5
zeek / dns
5
linux / network_connection
5
zeek / http
5
zeek / dce_rpc
4
m365 / audit
4
macos / file_event
4
windows / sysmon
4
windows / taskscheduler
4
windows / iis-configuration
4
windows / ntlm
3
linux / sshd
3
windows / registry_add
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
firewall
2
windows / security-mitigations
2
linux / syslog
2
spring / application
2
windows / dns-server
2
apache
2
onelogin / onelogin.events
2
windows / wmi
2
windows / applocker
2
linux / guacamole
1
windows / appmodel-runtime
1
django / application
1
linux / auth
1
huawei / bgp
1
windows / openssh
1
fortios / sslvpnd
1
linux / cron
1
juniper / bgp
1
windows / appxpackaging-om
1
windows / process_tampering
1
cisco / syslog
1
windows / smbserver-connectivity
1
windows / smbclient-connectivity
1
paloalto / file_event / globalprotect
1
zeek / x509
1
windows / capi2
1
windows / file_change
1
windows / raw_access_thread
1
paloalto / appliance / globalprotect
1
linux / vsftpd
1
windows / certificateservicesclient-lifecycle-system
1
windows / shell-core
1
nodejs / application
1
windows / microsoft-servicebus-client
1
python / application
1
windows / diagnosis-scripted
1
windows / file_executable_detected
1
ruby_on_rails / application
1
m365 / exchange
1
zeek / rdp
1
windows / smbclient-security
1
windows / file_rename
1
windows / sysmon_error
1
m365 / threat_detection
1
zeek / kerberos
1
windows / terminalservices-localsessionmanager
1
sql / application
1
windows / driver-framework
1
windows / sysmon_status
1
windows
1
velocity / application
1
cisco / duo
1
cisco / bgp
1
nginx
1
linux / sudo
1
cisco / ldp
1
windows / ldap
1
windows / dns-server-analytic
1
database
1
windows / lsa-server
1
windows / ps_classic_provider_start
1
windows / printservice-operational
1
linux / clamav
1
windows / printservice-admin
1

Sigma Rules Per Category (Nextron Private Feed)

Type
Count
windows / process_creation
543
windows / registry_set
97
windows / ps_script
92
linux / process_creation
72
windows / file_event
52
windows / image_load
48
windows / security
29
windows / wmi
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ntfs
5
windows / ps_module
5
windows / dns_query
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / registry_delete
4
windows / create_remote_thread
4
macos / process_creation
3
dns
3
windows / vhd
3
windows / ps_classic_script
3
windows / application-experience
3
windows / driver_load
3
windows / hyper-v-worker
3
windows / file_access
2
linux / file_delete
2
windows / kernel-shimengine
2
windows / smbclient-security
2
linux / Linux kernel module / THOR
2
windows / process_access
2
windows / windefend
2
windows / bits-client
2
windows / codeintegrity-operational
2
windows / file_delete
2
linux / file_event
2
windows / file_rename
1
windows / environment variable / THOR
1
linux / Unix user / THOR
1
windows / amsi
1
windows / application
1
windows / audit-cve
1
windows / registry-setinformation
1
windows / firewall-as
1

Tenable Nessus

Requirement: Privileged Scan

  • YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
Tutorial: https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

YARA Scanning with Nessus

  • You can only upload a single .yar file
  • Filesystem scan has to be activated
  • You have to define the target locations
  • The Nessus plugin ID will be 91990
  • Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
Tutorial: https://de.tenable.com/blog/threat-hunting-with-yara-and-nessus

Carbon Black

Tutorial: https://github.com/carbonblack/cb-yara-connector

FireEye EX

Tutorial: https://www.fireeye.com/blog/products-and-services/2018/12/detect-and-block-email-threats-with-custom-yara-rules.html