Ad

Signature-Base: YARA DB for Security Scanners

Signature-Base provides a curated YARA signature and IOC database for threat detection in scanners. It focuses on quality and structure for effective threat hunting.
Screenshot of Neo23x0/signature-base homepage

Signature-Base curates a database of high-quality YARA signatures and Indicators of Compromise (IOCs) designed for use with scanners like LOKI and THOR Lite. It addresses the need for reliable and structured threat intelligence feeds. The project uses a clear directory structure to organize rules and data for easy management and integration.

This project distinguishes itself through its focus on high-quality, minimal false positive YARA rules and a consistently structured organization. It offers a dedicated Threat Intel API Receiver for MISP and OTX feeds. The repository provides clear guidance on handling external variables within YARA rules, preventing common integration issues.

  • YARA Rules: A collection of YARA rules for detecting malicious files, processes, and network traffic with a focus on accuracy and minimal false positives.
  • IOC Files: Simple IOC files in CSV format for quick integration into various security tools.
  • Threat Intel Integration: Supports importing threat intelligence from MISP and OTX platforms for up-to-date detection capabilities.
  • Modular Structure: Organized into directories for YARA rules, IOCs, and threat intelligence, facilitating easy navigation and updates.
  • Developer Friendly: Includes clear documentation and FAQs to assist users in reporting false positives, contributing rules, and understanding the project.

The project is actively developed and maintained, with recent commits and an active development badge. The clear licensing and contribution guidelines suggest a commitment to community involvement and long-term sustainability.

Security analysts, threat hunters, and security engineers benefit from Signature-Base by providing a readily available and reliable source of YARA rules and IOCs. It streamlines threat detection workflows and enhances the effectiveness of security scanners, offering a valuable resource for proactive threat hunting and incident response.

Summarize:
Share:
Stars
2,988
Forks
672
Issues
15
Created
10 years ago
Commit
1 month ago
License
OTHER
Archived
No
Updated 17 days ago

Similar Repositories