Detection Rule List

Rule Name Rule Type Technique Count Creation Date
YARA_HDDInfo YARA 1 3 weeks, 5 days
YARA_BuildCommDCBAndTimeouts YARA 1 3 weeks, 6 days
Yara_LimeCRypter YARA 1 2 months, 4 weeks
YARA_SUSP_OBF_PyArmor YARA 1 2 months, 4 weeks
YARA_Check_Install_software YARA 1 3 months
YARA_SUSP_RLO_Exe_Extension_Spoofin YARA 1 3 months
YARA_SUSP_Direct_Syscall_Shellcode_Invocation YARA 1 3 months
YARA_NixImports_Loader2 YARA 1 3 months
YARA_NixImports_Loader YARA 1 3 months
YARA_POwershell_Special_Chars YARA 1 3 months
YARA_Base64 YARA 1 3 months
YARA_SUSP_OBF_NET_Reactor_Native_Stub YARA 1 3 months
YARA_SUSP_OBF_NET_Reactor YARA 1 3 months
YARA_PureCrypter YARA 1 3 months
YARA_OBF_NET_ConfuserEx_Packer YARA 1 3 months, 1 week
YARA_TrueCrypt_crypter YARA 1 3 months, 1 week
YARA_SUSP_OBF_NET_Reactor_Native YARA 1 3 months, 1 week
YARA_EasyCrypter YARA 1 3 months, 1 week
YARA_CRYPT_hXOR YARA 1 3 months, 1 week
YARA_OBF_NET_ConfuserEx YARA 1 3 months, 1 week
YARA_XOR_Hunt YARA 1 3 months, 1 week
YARA_SI_CRYPT_ScrubCrypt_BAT_Jan24 YARA 1 3 months, 1 week
Hunting_Rule_ShikataGaNai YARA 1 9 months, 1 week
YARA_Detect_createthreadpoolwait YARA 1 1 year, 3 months
YARA_Detect_XOR YARA 1 1 year, 4 months
YARA_Detect_ShortcutHiding YARA 1 1 year, 4 months
YARA_CheckName YARA 1 1 year, 4 months
YARA_Detect_SysmonUnload YARA 1 1 year, 4 months
YARA_DetectParentProcess YARA 1 1 year, 4 months
YARA_Detect_Interrupts YARA 1 1 year, 4 months

Filter