Skip to content


See what the GitHub community is most excited about today.

  1. A static analyzer for PE executables.

    YARA 522 108 Built by @JusticeRage @rc0r @gy741 @wesinator
  2. Repository of yara rules

    YARA 1,627 469 Built by @mmorenog @seifreed @jovimon @jholgui @Xumeiquer
  3. Program for determining types of files for Windows, Linux and MacOS.

    YARA 874 141 Built by @horsicq @hypn0chka @adoxa @d3adm4u5 @itsreallynick
  4. Signature base for my scanner tools

    YARA 732 208 Built by @Neo23x0 @JohnLaTwC @jonaslejon @yt0ng @cnotin
  5. Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

    YARA 600 128 Built by @CalebFenton @enovella @strazzere @circleous @Jasi2169
  6. Indicators of Compromises (IOC) of our various investigations

    YARA 555 114 Built by @marc-etienne @obilodeau @mFaou @nyx0 @pkalnai
  7. Please no pull requests for this repository. Thanks!

    YARA 514 151 Built by @DidierStevens
  8. Scripts for the Ghidra software reverse engineering suite.

    YARA 376 25 Built by @nezza
  9. PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.

    YARA 364 108 Built by @guelfoweb @2xyo @drego85 @rubinsaifi
  10. Hamburglar -- collect useful information from urls, directories, and files

    YARA 267 26 Built by @needmorecowbell @adi928 @tijko @jaeger-2601 @pingywon
  11. YARA Rules I come across on the internet

    YARA 131 35 Built by @mikesxrs @mybuddymichael
  12. Citizen Lab Malware Reports

    YARA 99 24 Built by @Te-k @jakubd @kkleemola @adulau @Cyberclues
  13. WALKOFF-enabled applications. #nsacyber

    YARA 86 28 Built by @JustinTervala @iadgovuser11 @coreyjrobins @dedgar1 @egk865
  14. Mass static malware analysis tool

    YARA 62 25 Built by @nheijmans @tcwaddell
  15. Repository of YARA rules made by McAfee ATR Team

    YARA 61 6 Built by @seifreed @3vangel1st
  16. A Web Malware Scanner

    YARA 52 12 Built by @sfaci
  17. Set of Yara rules for finding files using magics headers

    YARA 47 13 Built by @Xumeiquer @joanbono @wesinator
  18. EarthWorm/Termite 停止更新

    YARA 47 40 Built by @rootkiter
  19. Various Yara signatures (possibly to be included in a release later).

    YARA 40 16 Built by @mrexodia @Chandlr @techbliss @wesinator @Nukem9
  20. Yara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies

    YARA 36 13 Built by @Hestat
  21. CLI tool to analyze PE files

    YARA 33 14 Built by @Te-k @shadowbq
  22. Yara Dockerfile

    YARA 26 9 Built by @blacktop
  23. Investigation Planner for fast running analysis with predictable execution time. For example, static analysis.

    YARA 23 17 Built by @webstergd @boddumanohar @ms-xy @cynexit @zhanif3
  24. Malice Yara Plugin

    YARA 18 4 Built by @blacktop @wesinator
  25. IoC's, PCRE's, YARA's etc

    YARA 15 1 Built by @karttoon
Other: YARA
Other Languages
1C Enterprise ABAP ABNF ActionScript Ada Adobe Font Metrics Agda AGS Script Alloy Alpine Abuild AMPL AngelScript Ant Build System ANTLR ApacheConf Apex API Blueprint APL Apollo Guidance Computer AppleScript Arc AsciiDoc ASN.1 ASP AspectJ Assembly Asymptote ATS Augeas AutoHotkey AutoIt Awk Ballerina Batchfile Befunge Bison BitBake Blade BlitzBasic BlitzMax Bluespec Boo Brainfuck Brightscript Bro C C# C++ C-ObjDump C2hs Haskell Cabal Config Cap'n Proto CartoCSS Ceylon Chapel Charity ChucK Cirru Clarion Clean Click CLIPS Clojure Closure Templates Cloud Firestore Security Rules CMake COBOL CoffeeScript ColdFusion ColdFusion CFC COLLADA Common Lisp Common Workflow Language Component Pascal CoNLL-U Cool Coq Cpp-ObjDump Creole Crystal CSON Csound Csound Document Csound Score CSS CSV Cuda CWeb Cycript Cython D D-ObjDump Darcs Patch Dart DataWeave desktop Diff DIGITAL Command Language DM DNS Zone Dockerfile Dogescript DTrace Dylan E Eagle Easybuild EBNF eC Ecere Projects ECL ECLiPSe Edje Data Collection edn Eiffel EJS Elixir Elm Emacs Lisp EmberScript EML EQ Erlang F# F* Factor Fancy Fantom FIGlet Font Filebench WML Filterscript fish FLUX Formatted Forth Fortran FreeMarker Frege G-code Game Maker Language GAMS GAP GCC Machine Description GDB GDScript Genie Genshi Gentoo Ebuild Gentoo Eclass Gerber Image Gettext Catalog Gherkin Git Attributes Git Config GLSL Glyph Glyph Bitmap Distribution Format GN Gnuplot Go Golo Gosu Grace Gradle Grammatical Framework Graph Modeling Language GraphQL Graphviz (DOT) Groovy Groovy Server Pages Hack Haml Handlebars HAProxy Harbour Haskell Haxe HCL HiveQL HLSL HTML HTML+Django HTML+ECR HTML+EEX HTML+ERB HTML+PHP HTML+Razor HTTP HXML Hy HyPhy IDL Idris IGOR Pro Inform 7 INI Inno Setup Io Ioke IRC log Isabelle Isabelle ROOT J Jasmin Java Java Properties Java Server Pages JavaScript JFlex Jison Jison Lex Jolie JSON JSON with Comments JSON5 JSONiq JSONLD Jsonnet JSX Julia Jupyter Notebook KiCad Layout KiCad Legacy Layout KiCad Schematic Kit Kotlin KRL LabVIEW Lasso Latte Lean Less Lex LFE LilyPond Limbo Linker Script Linux Kernel Module Liquid Literate Agda Literate CoffeeScript Literate Haskell LiveScript LLVM Logos Logtalk LOLCODE LookML LoomScript LSL Lua M M4 M4Sugar Makefile Mako Markdown Marko Mask Mathematica MATLAB Maven POM Max MAXScript mcfunction MediaWiki Mercury Meson Metal MiniD Mirah Modelica Modula-2 Modula-3 Module Management System Monkey Moocode MoonScript MQL4 MQL5 MTML MUF mupad Myghty nanorc NCL Nearley Nemerle nesC NetLinx NetLinx+ERB NetLogo NewLisp Nextflow Nginx Nim Ninja Nit Nix NL NSIS Nu NumPy ObjDump Objective-C Objective-C++ Objective-J OCaml Omgrofl ooc Opa Opal OpenCL OpenEdge ABL OpenRC runscript OpenSCAD OpenType Feature File Org Ox Oxygene Oz P4 Pan Papyrus Parrot Parrot Assembly Parrot Internal Representation Pascal Pawn Pep8 Perl Perl 6 PHP Pic Pickle PicoLisp PigLatin Pike PLpgSQL PLSQL Pod Pod 6 PogoScript Pony PostCSS PostScript POV-Ray SDL PowerBuilder PowerShell Processing Prolog Propeller Spin Protocol Buffer Public Key Pug Puppet Pure Data PureBasic PureScript Python Python console Python traceback q QMake QML Quake R Racket Ragel RAML Rascal Raw token data RDoc REALbasic Reason Rebol Red Redcode Regular Expression Ren'Py RenderScript reStructuredText REXX RHTML Rich Text Format Ring RMarkdown RobotFramework Roff Roff Manpage Rouge RPC RPM Spec Ruby RUNOFF Rust Sage SaltStack SAS Sass Scala Scaml Scheme Scilab SCSS sed Self ShaderLab Shell ShellSession Shen Slash Slice Slim Smali Smalltalk Smarty SMT Solidity SourcePawn SPARQL Spline Font Database SQF SQL SQLPL Squirrel SRecode Template Stan Standard ML Stata STON Stylus SubRip Text SugarSS SuperCollider SVG Swift SystemVerilog Tcl Tcsh Tea Terra TeX Text Textile Thrift TI Program TLA TOML Turing Turtle Twig TXL Type Language TypeScript Unified Parallel C Unity3D Asset Unix Assembly Uno UnrealScript UrWeb Vala VCL Verilog VHDL Vim script Visual Basic Volt Vue Wavefront Material Wavefront Object wdl Web Ontology Language WebAssembly WebIDL Windows Registry Entries wisp World of Warcraft Addon Data X BitMap X Font Directory Index X PixMap X10 xBase XC XCompose XML Xojo XPages XProc XQuery XS XSLT Xtend Yacc YAML YANG YARA YASnippet ZAP Zephir Zig ZIL Zimpl
ProTip! Looking for recently updated YARA repositories? Try this search
You can’t perform that action at this time.