YARA rules, for your files & malware.
YARA rules aggregated from multiple resale-safe open-source sources, every rule compile-validated on the real engine, licenses vetted and signed. Load them into your EDR, DFIR scan, mail gateway.
What we added recently
A living feed: here is the coverage added to it, dated.
- +5 règles
- +4,654 règles
- +2,892 règles
- +2,004 règles
- +70 règles
- +1,232 règles
Broad coverage, without the duplicates or noise.
Malware-family signatures (loaders, stealers, ransomware, RATs) from multiple vendors.
Rules targeting intrusion tooling, implants and offensive C2 frameworks.
Webshells, weaponized documents, packers and exploitation artifacts.
Windows coverage, plus Linux and macOS via dedicated sources.
Every rule is compile-validated on the real YARA engine before delivery: nothing that fails to load. Rule names are deduplicated so the whole tree compiles in one shot.
Anywhere YARA runs.
Not a dump of random YARA repos.
Dozens of YARA repos merged into one feed, deduplicated by rule name.
Every rule is loaded on the real YARA engine: the ones that don’t compile are dropped.
Every rule is tested against a corpus of 4,000+ legitimate signed binaries (Windows drivers, PE, ELF). Those firing on clean software are removed, a validation report is included in the pack.
Every rule ships with a CACAO 2.0 investigation playbook (OASIS standard): confirm, pivot, scope, rule out false positives, respond — generated deterministically from the rule’s own facts (ATT&CK, D3FEND), 0 AI. No rule aggregator does this.
Aggregated sources under DRL / BSD / MIT / Apache / Unlicense, redistributable; our in-house rules kept apart in rules/exclusive/ under EULA.
In-house forged rules (e.g. authenticode certificates) add to the aggregate.
The feed is signed; you verify its integrity before applying it.
Each rule’s author and license are preserved, as DRL sources require.
A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.
↓ Download the demo pack .zipWhere do the rules come from?
From multiple permissively-licensed open-source YARA repos (DRL / BSD / MIT / Apache / Unlicense), aggregated, deduplicated and compile-validated, plus our own in-house forged set, 14 malware families, 209 malicious drivers and 7 offensive tools, kept apart in rules/exclusive/ under EULA. No non-commercial or GPL source enters the feed.
What does “compile-validated” mean?
Every rule is loaded on the real YARA engine before it enters the feed. If it doesn’t compile, it’s dropped, you only receive rules that load.
How do you handle false positives?
Beyond compile-validation, every rule goes through an anti-false-positive gate: we scan it against thousands of legitimate signed binaries (Windows drivers, PE, ELF). A rule firing on clean software is removed from the feed, never rewritten. The pack ships a dated validation report (VALIDATION.json): corpus tested, rules removed, residual false positives.
What if I also need Sigma?
Sigma is sold separately (€349/mo), or take the Sigma + YARA bundle at €549/mo (−21%): both feeds under one key.
Can I use it as an MSSP / redistribute it?
You use it within your organization, including to run detection on behalf of your clients. What you can’t do: resell or redistribute the pack as-is. The aggregated sources (DRL / BSD / MIT / Apache / Unlicense) remain redistributable under their own license, attribution kept; our in-house set (14 families, 209 drivers, 7 tools), kept apart in rules/exclusive/, are proprietary (EULA, use by the subscribing organization).
Ready to arm your scanners?
Annual subscription. Instant key. Cancel anytime.
Also need Sigma? Get the Sigma + YARA bundle, €549/mo (−21%)