Some of the detection rules for my public research. Feel free to contact me if you have an interesting sample, topic or you have a question about the rules.
In addition to the rules, there are some scripts (mostly in Python) that I developed in the analysis process.
All samples collected by my honeypots. They are all password-protected archive files with password infected.
In this section, you will find rules aimed to detect some of the interesting and unique malware samples.
In this section, you can find some of the general-purpose Yara rules to identify packers or anti-debug methods.