Valhalla Logo
currently serving 24372 YARA rules and 4655 Sigma rules
API Key

New Rules per Day

Newest YARA Rules

This table shows the newest additions to the YARA rule set

Rule
Description
Date
Ref
VULN_WordPress_CVE_2026_63030_Jul26
Detects scripts vulnerable to CVE-2026-63030: Unsafe handling of author__not_in in WordPress core (class-wp-query.php)
21.07.2026
SUSP_BTminer_Lib_Jul26
Detects usage of lib btminer in binaries, a cryptocurrency miner
21.07.2026
SUSP_Ruby_Host_Recon_Jul26
Detects host reconnaissance in Ruby source files
20.07.2026
MAL_Ruby_SleeperGem_Jul26
Detects SleeperGem credential stealer written in Ruby
20.07.2026
SUSP_SH_SUID_Backdoor_Jul26
Detects shell script creating SUID backdoor
20.07.2026
MAL_SH_SleeperGem_Jul26
Detects shell scripts which download and persist a backdoor on the system - seen being used in SleeperGem campaign
20.07.2026
MAL_Go_SSH_Backdoor_Jul26
Detects executables written in Golang which drop SSH keys from a ZIP archive
20.07.2026
HKTL_AutoScan_Credential_Harvester_Jul26
Detects AutoScan tool used to harvest tokens and keys issued by AI providers from open directories
20.07.2026
SUSP_Keylogger_Jul26
Detects a potential keylogger that captures keystrokes
16.07.2026
MAL_Kkernel_Keylogger_Jul26
Detects a kernel-mode keylogger for Windows, seen being used by APT-C-26
16.07.2026
MAL_Implant_Indicators_Jul26
Detects characteristics found in an unknown set of loaders and shellcodes
16.07.2026
MAL_C2_MalvexC2_Implants_Jul26
Detects MalvexC2 implants, which are often used for command and control communication in post-exploitation scenarios
16.07.2026
HKTL_LNX_Phantom_Implant_Jul26
Detects unknown implants called Phantom with the capability of hiding processes and executing fileless payloads
16.07.2026
MAL_LNX_Firmware_Implant_Jul26
Detects unknown Linux firmware implants
16.07.2026
MAL_GoLang_Veil_Stealer_Jul26
Detects golang based Veil stealer payload.
16.07.2026
SUSP_GoLang_Credential_Stealer_Indicators_Jul26
Detects golang binaries containing typical indicators of credential stealer payloads.
16.07.2026
SUSP_LNX_Leashtest_Jul26
Detects Leashtest. This binary is not malicious as-is, but its presence on a device likely indicates a compromise. It is used to test rudimentary functionality on the MIPS platform.
16.07.2026
MAL_LNX_Longleash_Jul26
Detects Longleash, a Linux backdoor capable of contacting its command and control (C2), hosting a web server, managing tunnels, and acting as both a C2 server and client.
16.07.2026
MAL_Jarleash_Jul26
Detects Jarleash, a Java backdoor giving remote access to the attacker using HTTP/FTP/SFTP/NETCAT protocols
16.07.2026
MAL_LNX_Dogleash_Jul26
Detects Dogleash, a Linux backdoor capable of executing arbitrary shellcodes
16.07.2026
MAL_JS_Miasma_Worm_Jul26
Detects Miasma Worm written in JavaScript and deployed via poisoned NPM packages; The worm establishes a persistent Node.js backdoor allowing additional payloads to be executed.
14.07.2026
MAL_DynLoader_Jul26
Detects Dynloader that uses PEB parsing and indirect syscalls to load and inject shellcode into local or remote processes
14.07.2026
MAL_Generic_Loader_Jul26
Detects malicious patterns of loaders that resolve functions from PEB and use syscalls to load payloads
14.07.2026
MAL_MacOS_Bash_Dropper_Jul26
Detects a dropper written in Bash that downloads DMGs, stages application bundles, modifies code signatures, and executes payloads.
14.07.2026
MAL_MacOS_Crash_Stealer_Jul26
Detects Crash stealer that exfiltrates browser data, cryptocurrency wallets, and sensitive application data.
14.07.2026
MAL_IronWorm_Jul26
Detects IronWorm credential stealer
14.07.2026
HKTL_VeeamDumper_Jul26
VeeamDumper, a credential extraction hacktool for Veeam Backup & Replication and Veeam One
13.07.2026
MAL_GigaWiper_Jul26
Detects GigaWiper and it's backdoor version
13.07.2026
MAL_USP_Backdoor_Jul26
Detects USP, a Linux backdoor using a udev rule that triggers the execution of a specified payload (binary or script)
13.07.2026
MAL_ELF_Backdoor_Jul26
Detects an ELF Linux backdoor seen in the wild in combination with the USP backdooring method
13.07.2026

Successful YARA Rules in Set

This table shows statistics of the best rules with lowest AV detection rates (rules created in the last 12 months, matches of the last 14 days)

Rule
Average AV Detection Rate
Sample Count
Info
VT
MAL_GuLoader_Shellcode_Oct22_3
0.0
20
SUSP_MAL_EXFIL_Stealer_Output_Characteristics_Sep22_1
0.04
180
SUSP_PY_OBFUSC_Berserker_Indicators_Dec22_1
0.21
14
SUSP_BAT_OBFUSC_Apr23_2
0.59
64
SUSP_Encrypted_ZIP_Suspicious_Contents_Jul23_1_File
0.64
11
SUSP_PUA_RustDesk_Apr23_1
0.68
22
SUSP_BAT_PS1_Combo_Jan23_2
0.71
45
SUSP_JS_OBFUSC_Feb23_2
1.04
1736
SUSP_WEvtUtil_ClearLogs_Sep22_1
1.12
43
SUSP_CryptBase_PE_Info_NOT_Cryptbase_Feb23
1.19
21
SUSP_OBFUSC_PY_Loader_Jun23_1
1.48
21
SUSP_Webshell_OBFUSC_Indicators_Aug22_1
2.07
14
SUSP_URL_Split_Jun23
2.5
18
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23
2.69
13
PUA_RuskDesk_Remote_Desktop_Jun23_1
2.78
18
SUSP_JS_Redirector_Mar23
2.81
108
SUSP_JS_Executing_Powershell_Apr23
3.14
274
SUSP_PY_Reverse_Shell_Indicators_Jan23_1
3.25
16
SUSP_OBFUSC_JS_Execute_Base64_Mar23
3.26
34
SUSP_Encoded_Registry_Key_Paths_Sep22_1
3.39
64
SUSP_PE_OK_RU_URL_Jun23
3.59
17
HKTL_Clash_Tunneling_Tool_Aug22_2
3.75
16
SUSP_PY_OBFUSC_Hyperion_Aug22_1
4.0
13
SUSP_BAT_OBFUSC_Apr23_1
4.0
16
SUSP_RANSOM_Note_Aug22
4.01
171
SUSP_OBFUSC_JS_Atob_Anomalies_Feb23_2
4.52
67
SUSP_BAT_PS1_Contents_Jan23_1
5.11
18
SUSP_OBFUSC_PS1_FormatStrings_Dec22_1
5.33
12
SUSP_BAT_OBFUSC_Apr23_4
5.35
26
SUSP_OBFUSC_BAT_Dec22_1
5.84
31

Latest YARA Matches with Low AV Detection Rate

This table lists the last matches with low AV detection rates (between 0 and 15 AV engines matched)

Rule
AVs
Hash
VT
PUA_ConnectWise_ScreenConnect_Mar23
10
f48b4d8a91a203a6cd41103697d1805c3d7344ed6858d2ae370caca3d10d0a6a
PUA_ConnectWise_ScreenConnect_Mar23
14
39a3031b30ff5b8f4d99c7845235c310ed3bb6332297d8e992dfc8abb70202c9
PUA_ConnectWise_ScreenConnect_Mar23
9
62460aaea2d78bd898eed4b87d414129f9f371219216febfd4a05e2f4bfbbfcb
SUSP_Two_Byte_XOR_PE_And_MZ
7
faa0588007f5eccd84ebe43d2dfa217cec615494ceb3d38303b2eaeb9da3edd0
SUSP_Four_Byte_XOR_PE_And_MZ
7
faa0588007f5eccd84ebe43d2dfa217cec615494ceb3d38303b2eaeb9da3edd0
SUSP_Two_Byte_XOR_PE_And_MZ
7
fac6199dedd7a2b251ccb397295f29dd1b44574592816d1d14a6ab4f92f9591e
PUA_ConnectWise_ScreenConnect_Mar23
10
4cf546ae7723412074d568771e2472a541c9b36252b065d687ad0a4a925223eb
SUSP_Four_Byte_XOR_PE_And_MZ
7
fac6199dedd7a2b251ccb397295f29dd1b44574592816d1d14a6ab4f92f9591e
SUSP_Four_Byte_XOR_PE_And_MZ
6
fa4fde98d0dd7b20285b0d1bb8eba4359cc73b12d57883a576012488bdea7e20
SUSP_Two_Byte_XOR_PE_And_MZ
8
f9ca733ad7bd82f0e34a493441e77749644e2b9773147d1d79b3abc260e6a8b6
SUSP_Four_Byte_XOR_PE_And_MZ
8
f9ca733ad7bd82f0e34a493441e77749644e2b9773147d1d79b3abc260e6a8b6
SUSP_Two_Byte_XOR_PE_And_MZ
6
fa4fde98d0dd7b20285b0d1bb8eba4359cc73b12d57883a576012488bdea7e20
MAL_PY_Compressed_B64_May24
2
bd1bc0c5666e511e76befeaebca99cb1e4ba54394ace3fe0579e2dfcbf60b3f5
SUSP_Four_Byte_XOR_PE_And_MZ
7
f1b101b33785daee8ed5d0fd9066fb6be4c996f31a54886e336874a1c8921b92
SUSP_Two_Byte_XOR_PE_And_MZ
7
f1b101b33785daee8ed5d0fd9066fb6be4c996f31a54886e336874a1c8921b92
SUSP_Two_Byte_XOR_PE_And_MZ
13
f15dac01dbbd230a7302b6d4f2549aca5c0e05d194ea42fe2068706265bc72d0
SUSP_Four_Byte_XOR_PE_And_MZ
13
f15dac01dbbd230a7302b6d4f2549aca5c0e05d194ea42fe2068706265bc72d0
SUSP_Four_Byte_XOR_PE_And_MZ
7
efbdb03d5dc8a42e9f697734d34de903999e05b6f5ba946ced270959bd8287ee
SUSP_Two_Byte_XOR_PE_And_MZ
7
efbdb03d5dc8a42e9f697734d34de903999e05b6f5ba946ced270959bd8287ee
SUSP_Four_Byte_XOR_PE_And_MZ
5
e87c291b8178ebd7708c96153c8ec4589888754d30ef75a68bc1ed4cb7475806

YARA Rules Per Category

This list shows the number of YARA rules in the subscribable categories (categories overlap as a rule can be in 'n' categories)

Tag
Count
Malware
7780
Threat Hunting (not subscribable, only in THOR scanner)
5979
APT
5078
Hacktools
4888
Webshells
2404
Exploits
744

Newest Sigma Rules

This table shows the newest additions to the Sigma rule set

Rule
Description
Date
Ref
Info
Potential Ctxmui.DLL Sideloading
Detects potential DLL sideloading of "ctxmui.dll"
12.07.2026
Renamed Solid PDF Creator.EXE Execution
Detects the execution of a renamed Solid PDF Creator binary.
12.07.2026
Scheduled Task Execution with Hardcoded IPv4 Address
Detects a process spawned by the Windows Task Scheduler whose command line contains a hardcoded IPv4 address. This may indicate the execution of a task previously created to reach out to attacker-controlled IP addresses for persistence or exfiltration.
10.07.2026
Scheduled Task Created via Remotely Hosted XML File
Detects schtasks.exe creating a new scheduled task using an XML definition file hosted on a remote UNC path (hostname or IP address). Threat actors may use this technique to load malicious task definitions from attacker-controlled or compromised file shares.
09.07.2026
SQL Server Query Output to File via OSQL.EXE
Detects SQL Server queries that output results to a file using the OSQL utility. This might indicate potential attempts to save sensitive data for exfiltration or for later analysis during post-exploitation activities. Even though this could be executed in legitimate contexts, this warrants immediate investigation.
05.07.2026
VirtualBox Binary Masquerading
Detects execution of binaries using VirtualBox-related filenames which are not the legitimate VirtualBox binaries. This may indicate an attempt to masquerade malicious binaries as VirtualBox components to evade detection.
05.07.2026
VMware Binary Masquerading
Detects execution of binaries using VMware-related filenames but are not the legitimate VMware binaries. This may indicate an attempt to masquerade malicious binaries as VMware components to evade detection.
05.07.2026
Credential Added to Public IPv4 Address via Cmdkey.EXE
Detects the addition of credentials to a public IPv4 address via cmdkey.exe. Adding credential to cmdkey allows attackers to store credentials for later use. Threat Actors may use this technique to access remote systems without being prompted for credentials and use automated scripts more effectively.
05.07.2026
Environment Variable Enumeration Via WMIC
Detects enumeration of environment variables via WMIC using the Win32_Environment class. Attackers query "environment get name,variablevalue" during host reconnaissance to discover paths, usernames, and configuration values useful for lateral movement or payload staging.
01.07.2026
File or Directory Enumeration Via WMIC
Detects file or directory enumeration via WMIC using the Win32_Directory or CIM_DataFile classes. Attackers use these classes to list directories or files on specific drives (e.g., "C:") during post-exploitation reconnaissance - a technique that bypasses traditional dir /ls command monitoring.
01.07.2026
User Account Password Property Manipulation Via WMIC
Detects manipulation of password-related properties on user accounts via WMIC against the Win32_UserAccount class. This covers direct password changes as well as policy modifications such as disabling password expiry or preventing password changes, all common persistence techniques to maintain access to a backdoor account.
01.07.2026
Startup Item Enumeration Via WMIC
Detects enumeration of startup items via WMIC using the Win32_StartupCommand class. Attackers query startup items to discover persistence mechanisms that automatically execute malicious binaries or scripts during system boot or user logon.
01.07.2026
Network Configuration Enumeration Via WMIC NicConfig
Detects enumeration of network interface configuration via WMIC using the "nicconfig" or "nic" aliases. Attackers commonly query NIC configuration during post-exploitation reconnaissance to discover IP addresses, MAC addresses, default gateways, and DNS servers — information used to map the network and pivot to additional targets.
01.07.2026
Suspicious Print Processor Driver Registry Modification
Detects modifications to Windows Print Processor Driver registry values where the configured DLL is not the default winprint.dll. This may indicate abuse of Print Processors for persistence or privilege escalation, as used by malware such as SprySOCKS.
26.06.2026
SOCKS Proxy Tunneling Invocation
Detects processes that invoke SOCKS proxy tunneling via command-line arguments. Threat actors abuse SOCKS-capable tools such as chisel, revsocks, or custom SSH tunnelers to establish covert C2 channels or bypass network controls.
23.06.2026
PowerShell Enumeration of Claude Code Chat History
Detects PowerShell scripts enumerating or reading files within the Claude Code conversation history directory. Claude Code stores conversation history as JSONL files under: %USERPROFILE%\.claude\projects\<hash>\<session>.jsonl Threat actors extract these files and apply regex matching to locate high-value secrets (cloud tokens, private keys, database passwords) before pivoting to infrastructure such as ESXi hosts via harvested SSH credentials.
11.06.2026
PowerShell One-Liner Targeting Claude Code Chat History
Detects PowerShell one-liners trying to enumerate or read files within the Claude Code conversation history directory. Claude Code stores conversation history as JSONL files under: %USERPROFILE%\.claude\projects\<hash>\<session>.jsonl Threat actors extract these files and apply regex matching to locate high-value secrets (cloud tokens, private keys, database passwords) before pivoting to infrastructure such as ESXi hosts via harvested SSH credentials.
11.06.2026
PowerShell One-Liner Credential Pattern Search
Detects PowerShell or pwsh one-liners whose command line combines a regex or string-matching primitive with common credential-related keywords. It might indicate an attempt of credential harvesting across local files, including config files, source code, chat history, etc. looking for secrets such as API keys, tokens, passwords, or SSH keys.
11.06.2026
GitHub Token Access Via GH CLI
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Malicious packages and scripts have been observed using these commands to silently exfiltrate the victim's stored GitHub authentication token.
08.06.2026
GitLab Token Access Via GLAB CLI
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
GitHub Token Access Via GH CLI - Linux
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitHub repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
GitLab Token Access Via GLAB CLI - Linux
Detects the GitLab CLI (glab) being used to retrieve stored authentication tokens. Threat actors might access such tokens to gain unauthorized access to GitLab repositories, CI/CD pipelines, and other resources, potentially leading to data exfiltration, code tampering, or further lateral movement within the victim's environment.
08.06.2026
Node or Bun Execution from Suspicious Locations - Linux
Detects the execution of build tools such as bun and node from potentially suspicious locations on Linux systems. In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute build tools such as bun and node from locations that are not commonly used for legitimate purposes.
08.06.2026
NPM Package Install Executed From Suspicious Location - Linux
Detects the execution of "npm install" via node on Linux from potentially suspicious directories. It might indicate a malicious package being installed or executed from a non-standard location. Attackers might use npm packages to execute malicious code on the victim's machine, potentially leading to data exfiltration, persistence, or further compromise of the system.
08.06.2026
Node or Bun Execution from Suspicious Locations
Detects the execution of build tools such as bun and node from potentially suspicious locations on Windows systems. In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute build tools such as bun and node from locations that are not commonly used for legitimate purposes.
08.06.2026
NPM Package Install Executed From Suspicious Location
Detects the execution of "npm install" via node.exe from potentially suspicious directories on Windows systems. It might indicate a malicious package being installed or executed from a non-standard location. Attacker might use npm packages to execute malicious code on the victim's machine, potentially leading to data exfiltration, persistence, or further compromise of the system.
08.06.2026
NTLM Hash Leak Via Curl NTLM Authentication
Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an attacker-controlled server, enabling offline cracking or relay attacks. When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials stored in LSASS — without requiring a plaintext password. This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
04.06.2026
Uninstall SystemComponent Registry Value Modification via CommandLine
Detects modification of the "SystemComponent" registry value in the "Uninstall" key through command line. Attackers modify this value to hide installed applications from "Programs and Features", often as part of persistence or defense evasion techniques.
04.06.2026
Audit Policy Category Discovery via Auditpol.EXE
Detects the use of auditpol.exe to query audit policy to discover which audit categories are enabled on the system. Attackers may use this information to identify potential gaps in security monitoring and adjust their tactics accordingly. Since, this require elevated privileges, unless it is being used by the administrator for legitimate purposes, it can be considered suspicious and warrants immediate attention.
04.06.2026
Hiding of an Installed Application from Application Wizard
Detects the SystemComponent DWORD registry value being set to 1 under an application's Uninstall key, which removes the application from "Programs and Features" and "Add or Remove Programs" visibility. Threat actors use this technique to hide installed applications, from normal administrative review, as part of persistence or defense evasion strategies.
04.06.2026

YARA/SIGMA Rule Count

Rule Type
Community Feed
Nextron Private Feed
Yara
1391
22981
Sigma
3591
1064

Sigma Rules Per Category (Community)

Type
Count
windows / process_creation
1351
windows / registry_set
219
windows / file_event
209
windows / ps_script
166
windows / security
160
linux / process_creation
139
windows / image_load
114
webserver
82
windows / system
74
macos / process_creation
69
aws / cloudtrail
55
proxy
54
linux / auditd
53
windows / network_connection
53
azure / activitylogs
42
windows / registry_event
40
azure / auditlogs
38
windows / ps_module
33
windows / application
32
windows / dns_query
27
windows / process_access
25
azure / signinlogs
24
opencanary / application
24
okta / okta
22
azure / riskdetection
19
windows / pipe_created
19
rpc_firewall / application
17
windows / windefend
17
linux
16
gcp / gcp.audit
16
github / audit
15
linux / file_event
15
bitbucket / audit
14
windows / file_delete
13
m365 / threat_management
13
cisco / aaa
13
windows / create_remote_thread
12
windows / driver_load
10
windows / registry_delete
10
kubernetes / application / audit
10
windows / codeintegrity-operational
10
dns
10
windows / create_stream_hash
9
windows / appxdeployment-server
9
windows / ps_classic_start
9
windows / msexchange-management
8
windows / firewall-as
8
fortigate / event
7
azure / pim
7
windows / file_access
7
windows / bits-client
7
gcp / google_workspace.admin
7
zeek / smb_files
7
antivirus
7
kubernetes / audit
6
windows / dns-client
6
jvm / application
5
zeek / dns
5
linux / network_connection
5
zeek / http
5
zeek / dce_rpc
4
m365 / audit
4
windows / sysmon
4
macos / file_event
4
windows / taskscheduler
4
windows / iis-configuration
4
windows / ntlm
3
linux / sshd
3
windows / registry_add
3
gcp / google_workspace.login
3
windows / wmi_event
3
windows / powershell-classic
3
firewall
2
linux / syslog
2
windows / security-mitigations
2
windows / dns-server
2
spring / application
2
apache
2
onelogin / onelogin.events
2
cisco / bgp
1
windows / lsa-server
1
windows / ps_classic_provider_start
1
windows / printservice-admin
1
database
1
linux / cron
1
windows / appmodel-runtime
1
windows / printservice-operational
1
linux / guacamole
1
huawei / bgp
1
django / application
1
linux / auth
1
linux / clamav
1
windows / applocker
1
windows / openssh
1
fortios / sslvpnd
1
juniper / bgp
1
windows / appxpackaging-om
1
windows / process_tampering
1
cisco / syslog
1
windows / smbserver-connectivity
1
windows / file_change
1
windows / smbclient-connectivity
1
windows / capi2
1
windows / shell-core
1
windows / raw_access_thread
1
nodejs / application
1
paloalto / file_event / globalprotect
1
windows / certificateservicesclient-lifecycle-system
1
windows / microsoft-servicebus-client
1
paloalto / appliance / globalprotect
1
linux / vsftpd
1
zeek / x509
1
python / application
1
windows / diagnosis-scripted
1
windows / smbclient-security
1
windows / file_executable_detected
1
m365 / exchange
1
zeek / rdp
1
windows / file_rename
1
ruby_on_rails / application
1
zeek / kerberos
1
windows / terminalservices-localsessionmanager
1
windows / sysmon_status
1
m365 / threat_detection
1
windows / driver-framework
1
sql / application
1
windows
1
windows / sysmon_error
1
velocity / application
1
cisco / duo
1
cisco / ldp
1
nginx
1
linux / sudo
1
windows / ldap
1
windows / wmi
1
windows / dns-server-analytic
1

Sigma Rules Per Category (Nextron Private Feed)

Type
Count
windows / process_creation
529
windows / registry_set
93
windows / ps_script
89
linux / process_creation
59
windows / file_event
49
windows / image_load
48
windows / security
29
windows / wmi
29
proxy
13
windows / system
13
windows / network_connection
9
windows / registry_event
8
windows / kernel-event-tracing
6
windows / ntfs
5
windows / dns_query
5
windows / ps_module
5
windows / sense
4
windows / pipe_created
4
webserver
4
windows / taskscheduler
4
windows / create_remote_thread
4
windows / registry_delete
4
macos / process_creation
3
dns
3
windows / ps_classic_script
3
windows / vhd
3
windows / hyper-v-worker
3
windows / application-experience
3
windows / driver_load
3
windows / file_delete
2
windows / smbclient-security
2
linux / Linux kernel module / THOR
2
linux / file_event
2
windows / bits-client
2
windows / codeintegrity-operational
2
windows / process_access
2
windows / windefend
2
windows / file_access
2
windows / kernel-shimengine
2
windows / registry-setinformation
1
windows / amsi
1
linux / file_delete
1
windows / application
1
windows / file_rename
1
windows / environment variable / THOR
1
windows / audit-cve
1
linux / Unix user / THOR
1
windows / posh_ps
1
windows / firewall-as
1

Tenable Nessus

Requirement: Privileged Scan

  • YARA Scanning with Nessus works only when scanning with credentials (privileged scan)
Tutorial: https://docs.tenable.com/nessus/Content/CredentialedChecksOnWindows.htm

YARA Scanning with Nessus

  • You can only upload a single .yar file
  • Filesystem scan has to be activated
  • You have to define the target locations
  • The Nessus plugin ID will be 91990
  • Only files with the following extensions can be scanned: .application, .asp, .aspx, .bat, .chm, .class, .cmd, .com, .cp, .csh, .dl, .doc, .docx, .drv, .exe, .gadget, .hta, .inf, .ins, .inx, .isu, .jar, .job, .jpeg, .jpg, .js, .jse, .jse, .jsp, .lnk, .msc, .msi, .msp, .mst, .paf, .pdf, .php, .pif, .ppt, .pptx, .ps1, .ps1xm, .ps2, .ps2xm, .psc1, .psc2, .reg, .rgs, .scf, .scr, .sct, .shb, .shs, .swf, .sys, .u3p, .vb, .vbe, .vbs, .vbscript, .ws, .wsf, .xls, .xls
Tutorial: https://de.tenable.com/blog/threat-hunting-with-yara-and-nessus

Carbon Black

Tutorial: https://github.com/carbonblack/cb-yara-connector

FireEye EX

Tutorial: https://www.fireeye.com/blog/products-and-services/2018/12/detect-and-block-email-threats-with-custom-yara-rules.html