chainguard-dev / malcontent

detect malicious program behaviors
Apache License 2.0
407 stars 26 forks source link

Integrate JP-CERT YARA rules #442

Closed tstromberg closed 2 weeks ago

tstromberg commented 2 weeks ago

It's possible that it's already being done indirectly, but let's confirm. They have some interesting nation-state actor rules.

egibs commented 2 weeks ago

Link for reference: https://github.com/JPCERTCC/jpcert-yara

I haven't done an exhaustive search but I'm not seeing any references to the rules in our third-party rules.