YARA Rule Builder
100% Client-Side
🌐 Web Shell (PHP / JSP)
🦠 Ransomware / Locker
💉 Cobalt Strike Beacon
🔑 Leaked Cloud Secrets
Strings: 0
Rule: Apt_Generic
Severity: High
Metadatos y Patrones
📂 Cargar Ejemplo
Nombre de la Regla (Rule Identifier)
Autor / Organización
Descripción de la Amenaza
Severidad (Threat Level)
Critical
High
Medium
Low
TLP Marking
TLP:CLEAR
TLP:GREEN
TLP:AMBER
TLP:RED
CVE Reference (Opcional)
Patrones de Detección ($strings / hex / regex)
Expresión de Condición (Condition)
Cualquiera de los patrones (any of them)
Todos los patrones (all of them)
Patrón + Límite de tamaño (any of them and filesize < 5MB)
Header PE ejecutable Windows (uint16(0) == 0x5A4D and 2 of them)
Condición personalizada...
Regla YARA Compilada (.yar)
📋 Copy
⬇ Download .yar