What the YARA feed covers
The figures below are measured on the pack you download, not on our working repositories. No detection logic is published here.
Measured on the pack published on 2026-09-04 (manifest 2026.09.04) — 19,914 entries in total.
Malware type
| Ransomware | 240 |
| Remote access trojan | 176 |
| Credential stealer | 136 |
| Loader | 130 |
| Unclassified | 19,232 |
Families covered
| Base | 4,296 |
| Trojan | 1,382 |
| Cert | 937 |
| Blocklist | 931 |
| Indicator | 848 |
| Malware | 525 |
| Ransomware | 461 |
| Apt | 357 |
| Maldriver | 209 |
| Backdoor | 206 |
| Rt | 155 |
| Arc | 126 |
| Exploit | 118 |
| Nimrev | 111 |
| Revil | 102 |
| Akira | 101 |
| Rusty | 98 |
| Cobaltstrike | 92 |
| Quasar | 85 |
| Tool | 75 |
| Wpbrutebot | 74 |
| Infostealer | 73 |
| Hacktool | 72 |
| Nodestealer | 65 |
| Xtunnel | 61 |
| Rugmi | 59 |
| Gcleaner | 58 |
| Chir | 57 |
| Hellokitty | 57 |
| Avoslocker | 53 |
| Cryptolocker | 52 |
| Medusalocker | 52 |
| Rustyclaw | 52 |
| Xworm | 52 |
| Mal | 50 |
| Vermin | 49 |
| Msil | 44 |
| Cobalt | 44 |
| Void | 44 |
| Aspxspy | 43 |
Rule origin
| Open-source base, validated and converted | 12,313 |
| Written by ThreatClaw | 7,601 |