Skip to content

Commit

Permalink
Added YARA rules from Malpedia
Browse files Browse the repository at this point in the history
  • Loading branch information
pyllyukko committed Nov 21, 2023
1 parent 4c54b8a commit 5e44e10
Show file tree
Hide file tree
Showing 2 changed files with 1,319 additions and 2 deletions.
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ For a complete list you can run `ansible-playbook --list-tasks harden.yml`.
* [ClamAV](https://www.clamav.net/) configuration (see [clamav.yml](tasks/clamav.yml))
* Configures `clamd` & `freshclam` by first generating fresh configurations with [clamconf](https://docs.clamav.net/manual/Usage/Configuration.html#clamconf)
* Configured ClamAV to unarchive with password "infected" (see [Passwords for archive files](https://docs.clamav.net/manual/Signatures/EncryptedArchives.html) & [ClamAV and ZIP File Decryption](https://blog.didierstevens.com/2017/02/15/quickpost-clamav-and-zip-file-decryption/))
* Downloads YARA rules from [Neo23x0](https://github.com/Neo23x0/signature-base), [GCTI](https://github.com/chronicle/GCTI), [Elastic](https://github.com/elastic/protections-artifacts), [YaraRules Project](https://yara-rules.github.io/blog/) & [JPCERT/CC](https://github.com/JPCERTCC/jpcert-yara) for [ClamAV to use](https://docs.clamav.net/manual/Signatures/YaraRules.html)
* Downloads YARA rules from [Neo23x0](https://github.com/Neo23x0/signature-base), [GCTI](https://github.com/chronicle/GCTI), [Elastic](https://github.com/elastic/protections-artifacts), [YaraRules Project](https://yara-rules.github.io/blog/), [JPCERT/CC](https://github.com/JPCERTCC/jpcert-yara) & [Malpedia](https://malpedia.caad.fkie.fraunhofer.de/) for [ClamAV to use](https://docs.clamav.net/manual/Signatures/YaraRules.html)
* [rkhunter](https://sourceforge.net/projects/rkhunter/) configuration (see [rkhunter.yml](tasks/rkhunter.yml))
* [Lynis](https://cisofy.com/lynis/) configuration (see [lynis.yml](tasks/lynis.yml))
* Configures AIDE (see [aide.yml](tasks/aide.yml))
Expand Down
Loading

0 comments on commit 5e44e10

Please sign in to comment.