MISP
Threat intelligence · Luxembourg
Read the tool profileDocumented support
Stores YARA rules, rule names, supported versions and optional test-sample hashes in a dedicated YARA object template.
An independent tool index
for incident response teams
Documented work with YARA rules or matching. Check the profile for scanning, rule handling and component requirements.
Filter these toolsEach entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.
Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.
13 tools with documented YARA support.
Threat intelligence · Luxembourg
Read the tool profileStores YARA rules, rule names, supported versions and optional test-sample hashes in a dedicated YARA object template.
Threat intelligence · Luxembourg
Read the tool profileUses YARA trackers on collected content and supports retrospective YARA hunts over historical data.
Digital forensics · France
Read the tool profileUses configured YARA rules for file matching. In the documented 10.3.x scanner, blocks currently falls back to file-mapping behavior for compatibility; legacy block scanning can miss whole-file matches. Timeouts and scan-method limits apply.
Digital forensics · Netherlands
Read the tool profileThe yara plugin scans files inside a forensic target using local rule files. Files above the configured maximum size are skipped; rule checking and decompression are configurable.
Detection and monitoring · France
Read the tool profileSignature detection scans file content, injected threads and process memory with configurable YARA rules. The OpenCTI connector can forward rules without validating them.
Threat intelligence · Italy
Read the tool profileThe local Yara analyzer scans files using documented community rule collections and operator-supplied signatures.
Malware analysis · Poland
Read the tool profileThe optional karton-yaramatcher service applies supplied YARA rules to pipeline files and tags matching samples. Rules are not included.
Detection and monitoring · Germany
Read the tool profileScans files and process memory using YARA-X, with YARA Forge Core rules as its default rule source. The project is beta; process-memory access has platform and permission limits.
Malware analysis · Poland
Read the tool profileSearches an indexed file collection using analyst-supplied YARA rules, with UrsaDB accelerating candidate selection.
Malware analysis · Luxembourg
Read the tool profileA YARA worker compiles local .yar rules and scans submitted file content. The worker disables itself when no usable rules are available.
Malware analysis · France
Read the tool profileRuns the configured Yara_Boosted analyzer through Cortex during submission analysis. Requires that analyzer to be installed and configured in the connected Cortex instance.
Feed automation · Germany
Read the tool profileIts yara operator runs YARA-X rules over finite byte input. It compiles source rules, does not accept precompiled rules, and documents module and input-size limits.
Malware analysis · Germany
Read the tool profileApplies bundled and custom YARA rules to files, process memory and other documented scan targets. Custom rules and scan-size limits are configurable.
A missing tool may support this feature without having been checked in this research pass.
Send a source or correction