YARA rules, for your files & malware.

YARA rules aggregated from multiple resale-safe open-source sources, every rule compile-validated on the real engine, licenses vetted and signed. Load them into your EDR, DFIR scan, mail gateway.

19 500+
YARA rules
multi-source
dozens of vetted repos
compile-validé
every rule loads on the real engine
Ed25519
signed, continuous updates

What we added recently

A living feed: here is the coverage added to it, dated.

  • +5 règles
  • +4,654 règles
  • +2,892 règles
  • +2,004 règles
  • +70 règles
  • +1,232 règles

Broad coverage, without the duplicates or noise.

Familles de malware

Malware-family signatures (loaders, stealers, ransomware, RATs) from multiple vendors.

APT & C2

Rules targeting intrusion tooling, implants and offensive C2 frameworks.

Webshells & maldocs

Webshells, weaponized documents, packers and exploitation artifacts.

Multi-OS

Windows coverage, plus Linux and macOS via dedicated sources.

Every rule is compile-validated on the real YARA engine before delivery: nothing that fails to load. Rule names are deduplicated so the whole tree compiles in one shot.

See the full coverage

Anywhere YARA runs.

EDR / AVengines that ingest YARA rules
DFIRVelociraptor, THOR/Loki, cold triage
Mail / fichiersmail gateways, share & upload scanning
yara CLIad-hoc scans, CI pipelines, sandbox

Not a dump of random YARA repos.

01
Multi-source aggregated

Dozens of YARA repos merged into one feed, deduplicated by rule name.

02
Compile-validated

Every rule is loaded on the real YARA engine: the ones that don’t compile are dropped.

03
Anti-false-positive, proven

Every rule is tested against a corpus of 4,000+ legitimate signed binaries (Windows drivers, PE, ELF). Those firing on clean software are removed, a validation report is included in the pack.

04
An investigation playbook per rule

Every rule ships with a CACAO 2.0 investigation playbook (OASIS standard): confirm, pivot, scope, rule out false positives, respond — generated deterministically from the rule’s own facts (ATT&CK, D3FEND), 0 AI. No rule aggregator does this.

05
Verified licensing, two regimes

Aggregated sources under DRL / BSD / MIT / Apache / Unlicense, redistributable; our in-house rules kept apart in rules/exclusive/ under EULA.

06
In-house rules

In-house forged rules (e.g. authenticode certificates) add to the aggregate.

07
Ed25519-signed

The feed is signed; you verify its integrity before applying it.

08
Attribution preserved

Each rule’s author and license are preserved, as DRL sources require.

Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip
Where do the rules come from?

From multiple permissively-licensed open-source YARA repos (DRL / BSD / MIT / Apache / Unlicense), aggregated, deduplicated and compile-validated, plus our own in-house forged set, 14 malware families, 209 malicious drivers and 7 offensive tools, kept apart in rules/exclusive/ under EULA. No non-commercial or GPL source enters the feed.

What does “compile-validated” mean?

Every rule is loaded on the real YARA engine before it enters the feed. If it doesn’t compile, it’s dropped, you only receive rules that load.

How do you handle false positives?

Beyond compile-validation, every rule goes through an anti-false-positive gate: we scan it against thousands of legitimate signed binaries (Windows drivers, PE, ELF). A rule firing on clean software is removed from the feed, never rewritten. The pack ships a dated validation report (VALIDATION.json): corpus tested, rules removed, residual false positives.

What if I also need Sigma?

Sigma is sold separately (€349/mo), or take the Sigma + YARA bundle at €549/mo (−21%): both feeds under one key.

Can I use it as an MSSP / redistribute it?

You use it within your organization, including to run detection on behalf of your clients. What you can’t do: resell or redistribute the pack as-is. The aggregated sources (DRL / BSD / MIT / Apache / Unlicense) remain redistributable under their own license, attribution kept; our in-house set (14 families, 209 drivers, 7 tools), kept apart in rules/exclusive/, are proprietary (EULA, use by the subscribing organization).

Ready to arm your scanners?

Annual subscription. Instant key. Cancel anytime.

€349 / month, billed annually €4,188 excl. tax

Also need Sigma? Get the Sigma + YARA bundle, €549/mo (−21%)

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.