ENNAENNA

Velociraptor vs YARA

GitHub Stats

3.9k
Stars
9.6k
609
Forks
1.6k
70
Issues
173
24d ago
Updated
3mo ago
-
License
BSD-3-Clause
Go
Language
C

About Velociraptor

Velociraptor is an endpoint visibility and collection tool designed for digital forensic investigations and incident response (DFIR). It allows security teams to hunt for artifacts across thousands of endpoints simultaneously, providing deep insights into system activities. Written in Go, Velociraptor is notable for its scalability and speed, enabling rapid response and comprehensive analysis in enterprise environments.

About YARA

YARA is the pattern matching swiss knife for malware researchers. It allows you to create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each rule consists of a set of strings and a boolean expression which determines its logic. YARA is used by security researchers, incident responders, and threat hunters to identify and classify malware samples, suspicious files, and network artifacts.

Platform Support

๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows
๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows

Tags

Velociraptor only

endpointhuntingdfirartifact-collection

YARA only

malwarepattern-matchingrulesclassification