Search engine for Yara Rules
Catches a webshell
Catches chinese PHP spam files (autospreaders)
Weevely Webshell - Generic Rule - heavily scrambled tiny web shell
Finds image files w/ PHP code in images
Catches a PHP Trojan
.ico PHP webshell - file <eight-num-letter-chars>.ico
Detect China Chopper ASPX webshell
Detect ASPXSpy
Laudanum Injector Tools - file file.asp
catch files
Contains references to system / monitoring tools
This rule finds for base64 strings
tweetable-polyglot-png: https://github.com/DavidBuchanan314/tweetable-polyg....
Microsoft Visual C++ 5.0
Entropy Check
recent Emotet packer pdb string
JavaScript Obfuscation Detection
jjencode detection
Detects payload generated by exe2hex
Rules for TCP Portscanner VX.X by WinEggDrop
Windows Credential Editor
Detects solarwinds credential stealers like e.g. solarflare via the touched....
Detects .NET red/black-team tools via name
Detects c# red/black-team tools via typelibguid
Detects all QuarksPWDump versions