

YARA Rules and Scripts

Hello! This repository contains a set of my detection rules to improve detection and hunting visibility and context. Where applicable, YARA has its description with the name and the variant of the malware family.

YARA Rules

The YARA-rules directory contains the following YARA rules :


The scripts directory contains the following scripts :

These scripts are designed to extract configuration and decrypt strings from malware samples that the YARA rules detect.


If you have any questions or need further information, you can contact me at: