currently serving 24673 YARA rules and 4730 Sigma rules
API Key
New Rules per Day
Newest YARA Rules
This table shows the newest additions to the YARA rule set
Rule
Description
Date
Ref
MAL_CVE_2026_88771_NetScaler_Webshell_Dropper_Oct26
Detects script that enables PHP engine in httpd.conf and drops webshells with command execution capabilities on NetScaler, related to CVE-2026-88771
03.10.2026
MAL_CVE_2026_88771_Perl_BindShell_Oct26
Detects Perl bind shell with socket-to-shell redirection and cron persistence, related to CVE-2026-88771
03.10.2026
MAL_CVE_2026_88771_NetScaler_EPA_Bypass_Oct26
Detects post-exploitation script that disables EPA endpoint security checks and unbinds authentication policies on NetScaler, related to CVE-2026-88771
03.10.2026
SUSP_Chmod_BinSh_Priv_Escalation_Oct26
Detects suspicious chmod on /bin/sh commonly used for privilege escalation via SUID/SGID bit setting
03.10.2026
PUA_Platypus_Oct26
Detects Platypus an open-source fleet management hub, it's can be used as a C2 framework by attackers.
03.10.2026
MAL_Platypus_C2_Agent_Bootstrap_Oct26
Detects Platypus C2 agent bootstrap script that downloads and executes a remote agent binary, related to CVE-2026-88771
03.10.2026
MAL_LNX_Cling_Worm_Oct26
Detects Cling worm that propagates by exploiting vulnerable IoT devices and uses STUN traffic for command and control.
03.10.2026
SUSP_Hidden_File_Download_Oct26
Detects hidden file being downloaded in suspicious location
02.10.2026
MAL_B64_EXPL_CVE_2026_88771_Oct26
Detects base64 encoded CVE-2026-88771 post-exploitation script
02.10.2026
MAL_B64_Encoded_Webshell_Oct26
Detects base64 encoded command used in webshell to execute user input
02.10.2026
MAL_Generic_Loader_Oct26
Detects generic loaders that load other payloads into memory and execute them
02.10.2026
SUSP_LNX_IoT_Shell_Exec_Oct26
Detects ELF files containing HTTP based shell command execution patterns
02.10.2026
SUSP_JS_Loader_Oct26
Detects JavaScript code that spawn process commonly used by droppers and stagers to execute payloads
01.10.2026
SUSP_OBFUSC_VBS_Object_Creation_Sep26
Detects obfuscated VBS script that obfuscate object creation using replace
30.09.2026
MAL_Animate_Clipper_Sep26
Detects Animate Clipper which targets cryptocurrency wallets and other credentials. The malware may also execute additional payloads received from a remote server.
30.09.2026
SUSP_LNX_PAM_Potential_Backdoor_Sep26
Detects potential PAM backdoor activity on Linux. This PAM module's pam_sm_authenticate function may be tampered with to bypass authentication.
30.09.2026
MAL_Amatera_Stealer_Sep26
Detects Amatera credential stealer with extensive anti analysis and evasion features.
29.09.2026
MAL_Kothamine_Backdoor_Sep26
Detects Kothamine backdoor, capable of executing commands and exfiltrating data, it abuses tailcat to hide it's C2 communications
29.09.2026
SUSP_WebArchive_Pipe_To_Interpreter_Sep26
Detects scripts that fetch a payload through the Internet Archive's Wayback Machine (web.archive.org) and pipe it into an interpreter or shell, as seen in the DirtyBlanket npm package campaign
29.09.2026
SUSP_LNX_Systemd_Service_Tor_SOCKS_Proxy_Sep26
Detects systemd service units which route the service's traffic through a local Tor SOCKS proxy (port 9050/9150) via proxy environment variables, as seen in the DirtyBlanket npm campaign to hide C2 communication
29.09.2026
EXPL_CVE_2026_88772_POC_Sep26
Detects POC for Citrix NetScaler DTLS memory overflow, CVE-2026-88772
28.09.2026
SUSP_EXPL_CVE_2026_88771_Sep26
Detects potential exploitation indicator for Citrix NetScaler PreAuth Command Injection CVE-2026-88771
28.09.2026
MAL_Remus_Stealer_Sep26
Detects Remus stealer malware. Remus is a stealthy information stealer specialized in credential and crypto wallet harvesting.
28.09.2026
MAL_JS_WebSocket_RAT_Sep26
Detects a JavaScript websocket RAT seen being used by DPRK threat actors in npm supply chain attacks
28.09.2026
SUSP_JS_Info_Gathering_Sep26
Detects JavaScript files collecting host information such as OS platform, architecture, release, uptime, CPUs, home directory and Node.js version, which is typical for system reconnaissance by RATs
28.09.2026
SUSP_JS_Process_Execution_Sep26
Detects JavaScript spawning system utilities such as reg, wmic, pgrep, schtasks or systemctl with piped stdio, which is typical for reconnaissance and persistence handling by RATs
28.09.2026
SUSP_JS_VBS_Dropper_Sep26
Detects JavaScript writing a VBS script to disk that executes commands via CreateObject and Run, which can be used for persistence on Windows
28.09.2026
Successful YARA Rules in Set
This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)
Rule
Average AV Detection Rate
Sample Count
Info
VT
Latest YARA Matches with Low AV Detection Rate
This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)
Rule
AVs
Hash
VT
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
8
5bd344ee48443ec97f5408fcea28ae52e99c76fe0c6ef14dabf2f9c41bf96b70
SUSP_Base64_Encoded_Hex_Encoded_Code
8
5bd344ee48443ec97f5408fcea28ae52e99c76fe0c6ef14dabf2f9c41bf96b70
SUSP_Base64_Encoded_Hex_Encoded_Code
8
5caed5029217d9703bac1fcf24671c94ad512c225f4dce07089ea9ce652776f4
SUSP_Base64_Encoded_Hex_Encoded_Code
8
70efbf38ecb04207837ca664d7d63000020fee4bb4d62fc9314c5df560c1999c
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
8
5caed5029217d9703bac1fcf24671c94ad512c225f4dce07089ea9ce652776f4
SUSP_OBFUSC_Base64_Hex_Encoded_Apr19
8
70efbf38ecb04207837ca664d7d63000020fee4bb4d62fc9314c5df560c1999c
SUSP_PS1_Encoded_Defender_AV_Exclusion_Pattern_Mar22_1
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
SUSP_OBFUSC_PS1_Encoded_PowerShell_Commands_Apr22_1
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
SUSP_Base64_Encoded_WhomAmI_Wide
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
SUSP_Encoded_Registry_Key_Paths_Sep22_1
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
SUSP_OBFUSC_Encoded_Folder_Mar22_1
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
SUSP_Base64_Encoded_WScriptShell
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
SUSP_Wextract_Anomaly_Unsigned_May23
7
97a1bf5dc33f817beca7411a5f59268d0ca55d762209657ea849d63fa41f86ad
SUSP_OBFUSC_Base64_Hacktool_Indicator_Feb22_1
14
96c8ed7c9eb2c00ae44e8cafc0a1fcdbedde5aa67e16ee7d8c37a40d43c8dba6
YARA Rules Per Category
This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)
Tag
Count
Malware
7920
Threat Hunting (not subscribable, only in THOR scanner)
6094
APT
5104
Hacktools
4916
Webshells
2409
Exploits
753
Newest Sigma Rules
This table shows the newest additions to the Sigma rule set
Rule
Description
Date
Ref
Info
Suspicious Crontab Pipeline Injection
Detects suspicious crontab pipeline injection patterns where an attacker reads the
existing crontab with crontab -l, appends a malicious entry via echo, and writes it
back using crontab - (stdin mode), as legitimate crontab edits are done
interactively via crontab -e rather than from stdin.
30.09.2026
Bulk Process Termination via PowerShell Whitelist Exclusion
Detects PowerShell commands that enumerate all running processes and terminate those
not matching a hardcoded whitelist. This pattern is characteristic of ransomware and
destructive malware that kills security tools, backup agents, and database services
before payload execution.
30.09.2026
ETW Bypass via EtwEventWrite Memory Patch
Detects ETW bypass attempts via memory patching of the EtwEventWrite function in ntdll.dll.
Threat actors may use this technique to evade detection by security tools that rely on ETW for monitoring.
30.09.2026
Process Termination via PowerShell Enumeration Pipeline
Detects PowerShell commands that enumerate all running processes and terminate them
via a pipeline or loop. It is commonly observed in post-exploitation tooling and ransomware
precursor activity where specific process categories such as security tools, backup agents,
or database services are killed before payload execution.
30.09.2026
Potentially Suspicious Image Load of Tlscsp.dll
Detects tlscsp.dll ("Microsoft Remote Desktop Services Cryptographic Utility")
loaded by a process outside standard Microsoft or system directories. The DLL
contains a hardcoded RC4 key exposed through its LsCsp_EncryptHwid export,
providing a predictable cryptographic primitive that malware can leverage to
decrypt payloads or encrypt data without embedding custom crypto code. Loading
this DLL from an unexpected location is potentially suspicious, as threat actors
abuse a trusted system component to perform cryptographic operations natively,
bypassing detection that would otherwise flag unsigned or anomalous crypto implementations.
24.09.2026
Potential PowerShell Keylogger via Low-Level Keyboard Hook
Detects PowerShell ScriptBlock containing inline C# that installs a low-level keyboard hook
via SetWindowsHookEx with the WH_KEYBOARD_LL hook type. Attackers use Add-Type to compile
and execute a keylogger entirely in memory, intercepting all keystrokes system-wide without
dropping a standalone binary to disk. The presence of CallNextHookEx confirms a chained hook
implementation, distinguishing it from benign API references.
16.09.2026
Potential PowerShell Screen Capture via Win32 GDI BitBlt
Detects PowerShell ScriptBlock using the Win32 GDI BitBlt API to capture screen content.
Attackers use this native approach to silently copy display pixel data without dropping a
standalone capture binary, a technique commonly observed in keyloggers, RATs and spyware.
16.09.2026
Suspicious System Info Discovery via CurrentVersion Registry Key
Detects attempts to query values under 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
for system reconnaissance when initiated from a suspicious location. This key exposes a
broad set of host profiling data including OS edition, build details, installation type
and patch level. Attackers read these values during post-exploitation to profile the target
before selecting a payload or escalation path, often executing from user-writable directories
such as Temp, Downloads, or Public folders.
14.09.2026
Suspicious PowerShell System Reconnaissance Via DotNET Environment Class
Detects PowerShell commands that access .NET [Environment] class properties for
system reconnaissance when spawned from a suspicious location. Attackers use these
properties to enumerate user and session context, system hardware info, OS version,
filesystem paths and/or environment variables during post-exploitation profiling prior
to payload staging or lateral movement. Rather than relying on external tools or registry
queries, attackers may gather system information directly from the .NET Environment class
while executing from user-writable directories such as Temp, Downloads, or Public folders.
14.09.2026
PowerShell Script Execution From Environment Variable - ScriptBlock
Detects PowerShell loading and executing a script stored inside an environment variable.
Attackers use this to hide the malicious code from command-line logs and security tools,
since the actual script is never written to disk or shown in the process arguments.
08.09.2026
PowerShell Script Execution From Environment Variable - CommandLine
Detects PowerShell loading and executing a script stored inside an environment variable.
Attackers use this to hide the malicious code from command-line logs and security tools,
since the actual script is never written to disk or shown in the process arguments.
08.09.2026
Kernel Driver Service ImagePath Set by Potentially Suspicious Process
Detects kernel driver service ImagePath registry values being set by potentially suspicious processes.
This can indicate attempts to load kernel drivers without using the standard Service Control Manager,
which malware may use to maintain persistence or employ BYOVD techniques often used in EDR killer tools.
It's recommended to first baseline this rule in your environment and adjust it accordingly before enabling
it in production.
02.09.2026
Kernel Driver Service ImagePath Pointing to Non-Standard Location
Detects kernel driver service ImagePath registry values that point to non-standard locations outside typical Windows driver directories.
This may indicate attempts to load malicious or vulnerable kernel drivers for persistence or privilege escalation, a technique commonly
observed in EDR-killer tools that drop a driver to a non-standard location before loading it for further exploitation. It's recommended
to first baseline this rule in your environment and adjust it accordingly before enabling it in production.
02.09.2026
PUA - Tailcat Saved Key Generation - Linux
Detects the generation of Tailcat saved keys that persist the secret between multiple sessions. Using Tailcat persistently is unusual in corporate environments.
02.09.2026
PUA - Tailcat Saved Key Generation - Windows
Detects the generation of Tailcat saved keys that persist the secret between multiple sessions. Using Tailcat persistently is unusual in corporate environments.
02.09.2026
Remote PDF Opened via Explorer with HTTP URL
Detects explorer.exe being invoked with an HTTP URL pointing to a remote PDF file.
Attackers use this technique to display a decoy document while a malicious payload
executes in the background, distracting the victim after LNK-based initial access.
explorer.exe is not normally launched from the command line with a remote HTTP path;
its appearance in such a context is a strong indicator of a scripted attack chain.
31.08.2026
EventLog Metadata Inspection Via Wevtutil
Detects the eventlog metadata inspection attempt via wevtutil.exe.
Threat actors use these to verify whether security logging is active and gauge
how much time they have before entries are overwritten, before performing intrusive actions.
27.08.2026
Email Protocol Access Via Curl
Detects curl.exe being used to access email servers over IMAP or SMTP protocols.
Curl natively supports IMAP/IMAPS and SMTP/SMTPS, allowing attackers to interact with
mailboxes directly from the command line - reading inbox contents, selecting folders,
or sending messages - without deploying a dedicated mail client. This technique is used
for C2 communication via corporate mail infrastructure and for data exfiltration, blending
with legitimate email traffic.
27.08.2026
Renamed Node.js Binary Execution
Detects the execution of a renamed Node.js JavaScript runtime, normally named "node.exe".
Node.exe is the executable file for the Node.js JavaScript runtime and is typically used
to execute JavaScript code outside a web browser environment. Threat actors may
rename the Node.js executable to a random name to run malicious scripts stealthily.
26.08.2026
Senstitive File Access via Cmd Utility
Detects the usage of windows inbuilt cmd.exe utility to access sensitive files such as configuration files,
certificate files, and password files. It might indicate an adversary attempting to access sensitive files
for credential access or collection purposes via reverse shell or cli interaction.
26.08.2026
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
19.08.2026
SSH Known Hosts File Deleted
Detects deletion of SSH known_hosts files via file deletion events.
Complements the proc_creation variant by catching cases where the shell handles
the operation directly (e.g. bare redirects, unlink syscalls) without spawning
a traceable child process.
Attackers remove known_hosts to erase lateral movement destinations and suppress
SSH host key mismatch warnings.
19.08.2026
Linux Log File Content Cleared or Deleted via CLI Utilities
Detects unusual CLI-based methods to clear or delete Linux log file contents, including
truncating to zero size, overwriting with /dev/null, and other methods. These techniques
are commonly used by attackers and ransomware to destroy forensic evidence before or after
malicious activity.
19.08.2026
Logging Daemon Force Killed via CommandLine
Detects use of kill, killall, pkill, or other command line methods to forcefully terminate
common Linux logging and auditing services. Threat actors or malware may use this technique
to silence audit trails before encryption or exfiltration.
19.08.2026
Logging Service Stopped via Service Command
Detects use of the legacy service command to stop common Linux logging and auditing services. The service
command wraps SysV init scripts and remains functional on systemd-based distributions via compatibility shims.
Attackers use this to stop logging with a command that blends into older administration patterns.
19.08.2026
Logging Service Stopped or Disabled via Systemctl
Detects use of systemctl to stop, kill, mask, or disable common Linux logging and auditing services (rsyslog, syslog-ng, auditd, systemd-journald).
Attackers and ransomware use this to silence audit trails before encryption or exfiltration.
Masking a service additionally prevents it from being restarted by other processes.
19.08.2026
SSH Known Hosts File Removed or Cleared
Detects removal or clearing of SSH known_hosts files via common CLI utilities.
Attackers delete known_hosts to erase evidence of lateral movement destinations and to
suppress SSH host key mismatch warnings when reconnecting to a host whose key has been changed.
19.08.2026
New User Account Creation Attempt Via ADSI
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces)
using either the WinNT or LDAP provider. This is an uncommon method to create user accounts
and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
New User Account Creation Attempt Via ADSI in CommandLine
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
13.08.2026
PowerShell Live Kernel Dump
Detects PowerShell scripts or commands that create live kernel dumps.
While live kernel dumps are a legitimate diagnostic mechanism, they are increasingly
abused by threat actors to read sensitive process memory such as LSASS without opening
a direct process handle, bypassing traditional process-access based detections.
10.08.2026
YARA/SIGMA Rule Count
Rule Type
Community Feed
Nextron Private Feed
Yara
1094
23579
Sigma
3617
1113
Sigma Rules Per Category (Community)
Type
Count
windows / process_creation
1359
windows / registry_set
219
windows / file_event
211
windows / ps_script
167
windows / security
164
linux / process_creation
142
windows / image_load
115
webserver
86
windows / system
74
macos / process_creation
69
aws / cloudtrail
57
proxy
55
linux / auditd
54
windows / network_connection
53
azure / auditlogs
44
windows / registry_event
40
azure / activitylogs
35
windows / ps_module
33
windows / application
32
windows / dns_query
28
windows / process_access
25
opencanary / application
24
okta / okta
22
azure / riskdetection
19
windows / pipe_created
19
azure / signinlogs
18
rpc_firewall / application
17
windows / windefend
17
linux
16
linux / file_event
16
gcp / gcp.audit
16
github / audit
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / create_stream_hash
9
windows / appxdeployment-server
9
antivirus
9
windows / ps_classic_start
9
windows / firewall-as
8
windows / msexchange-management
8
fortigate / event
7
windows / file_access
7
azure / pim
7
windows / bits-client
7
gcp / google_workspace.admin
7
zeek / smb_files
7
kubernetes / audit
6
windows / dns-client
6
jvm / application
5
zeek / dns
5
linux / network_connection
5
zeek / http
5
zeek / dce_rpc
4
m365 / audit
4
macos / file_event
4
windows / sysmon
4
windows / taskscheduler
4
windows / iis-configuration
4
windows / ntlm
3
linux / sshd
3
windows / registry_add
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
windows / applocker
2
firewall
2
windows / security-mitigations
2
linux / syslog
2
windows / dns-server
2
spring / application
2
apache
2
windows / wmi
2
onelogin / onelogin.events
2
windows / printservice-operational
1
linux / clamav
1
windows / ldap
1
django / application
1
linux / auth
1
linux / cron
1
fortios / sslvpnd
1
huawei / bgp
1
windows / appmodel-runtime
1
windows / openssh
1
windows / process_tampering
1
cisco / syslog
1
linux / guacamole
1
juniper / bgp
1
windows / appxpackaging-om
1
windows / file_change
1
windows / smbclient-connectivity
1
windows / shell-core
1
windows / raw_access_thread
1
nodejs / application
1
paloalto / file_event / globalprotect
1
windows / capi2
1
windows / smbserver-connectivity
1
paloalto / appliance / globalprotect
1
linux / vsftpd
1
zeek / x509
1
windows / certificateservicesclient-lifecycle-system
1
python / application
1
windows / microsoft-servicebus-client
1
windows / file_executable_detected
1
windows / diagnosis-scripted
1
windows / smbclient-security
1
windows / file_rename
1
windows / sysmon_error
1
m365 / exchange
1
zeek / rdp
1
windows / sysmon_status
1
ruby_on_rails / application
1
zeek / kerberos
1
windows / terminalservices-localsessionmanager
1
m365 / threat_detection
1
windows / driver-framework
1
velocity / application
1
windows
1
linux / sudo
1
sql / application
1
cisco / duo
1
cisco / ldp
1
nginx
1
windows / dns-server-analytic
1
windows / ps_classic_provider_start
1
windows / printservice-admin
1
database
1
cisco / bgp
1
windows / lsa-server
1
Sigma Rules Per Category (Nextron Private Feed)
Type
Count
windows / process_creation
549
windows / registry_set
97
windows / ps_script
95
linux / process_creation
73
windows / file_event
52
windows / image_load
49
windows / security
29
windows / wmi
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ntfs
5
windows / ps_module
5
windows / dns_query
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / registry_delete
4
windows / create_remote_thread
4
macos / process_creation
3
dns
3
windows / ps_classic_script
3
windows / application-experience
3
windows / vhd
3
windows / hyper-v-worker
3
windows / driver_load
3
linux / file_delete
2
windows / file_delete
2
linux / file_event
2
windows / kernel-shimengine
2
linux / Linux kernel module / THOR
2
windows / smbclient-security
2
windows / environment variable / THOR
2
windows / process_access
2
windows / bits-client
2
windows / windefend
2
windows / codeintegrity-operational
2
windows / file_access
2
windows / firewall-as
1
windows / file_rename
1
linux / Unix user / THOR
1
windows / application
1
windows / audit-cve
1
windows / registry-setinformation
1
windows / amsi
1
Tenable Nessus
Requirement: Privileged Scan
- YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
YARA Scanning with Nessus
- You can only upload a single .yar file
- Filesystem scan has to be activated
- You have to define the target locations
- The Nessus plugin ID will be 91990
- Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
