Press ReleasesJune 30, 2020

ReversingLabs Unveils 100+ Open Source YARA Rules for Threat Hunters at Inaugural REVERSING 2020 Summit

FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us

More Than One Thousand Researchers and Threat Hunters First to Preview Newly Published YARA Rules for Detecting Top Windows and Linux Malware Families

100 plus open source yara rules

CAMBRIDGE, Mass. - June 30, 2020 – ReversingLabs, the leading provider of explainable threat intelligence solutions, made a sizable contribution to the open source community today, publishing 128 of its rigorously tested YARA rules to GitHub for the first time. Announced at ReversingLabs inaugural threat hunter summit REVERSING 2020, these now publicly available rules enable threat defenders to detect a multitude of prominent and prevalent malware downloaders, viruses, trojans, exploits, and ransomware, including WannaCry, Ryuk, GandCrab, TrickBot and others. With free access to these rules that generate precise and accurate results and attribution, threat defenders now have the ability to more quickly pivot from a malware detection event to threat response.

“Knowing that a YARA rule has detected ransomware with high degree of precision can mean the difference between a prevented attack and the one that slips by because it was left waiting for investigation to elevate its importance,” said Tomislav Pericin, Chief Software Architect and Co-Founder, ReversingLabs. “Threat hunters can confidently add these YARA rules to their toolkit. They are built to provide zero false-positive detections. Only those that pass rigorous testing against our 10 billion unique binaries get published, ensuring quality and efficacy.”

Leveraging ReversingLabs extensive repository of 10 billion goodware and malware samples, deep understanding of destructive objects, and its analysts’ nearly two decades of threat hunting experience, these malware detection rules help threat hunters and other threat defenders attribute malware by type and family or variety to expedite threat response processes and reduce malware infection risk for their organizations. The rules can also be used to upskill threat defenders by showcasing high quality malware detection rules that consist of patterns that identify malicious code blocks.

Rule Categories

In its first release of open source YARA rules, ReversingLabs focused on those that would help close detection gaps for deployed security solutions by focusing on the most destructive malware types, including: WannaCry, Multigrain, MedusaLocker, Kovter, Ryuk, GandCrab, Crysis, TrickBot, Emotet, Dridex, and CurveBall (CVE-2020-0601).

Availability & Support

The initial list of YARA rules can be accessed immediately via ReversingLabs GitHub repository. ReversingLabs will be responsible for maintaining the repository, providing regular updates, and adding new rules over time for detecting the latest threats. For questions, suggestions and guidance, threat hunters can contact ReversingLabs at support@reversinglabs.com or open an issue on the GitHub repository.

REVERSING 2020

ReversingLabs first 100 open source YARA rules were announced in a presentation by Pericin during REVERSING 2020, a free virtual summit that brought together more than 1,300 threat hunters, thought leaders, and security practitioners to discuss YARA best practices to assist in hunting, identifying, and classifying malware samples. Keynote speaker Vitali Kremez discussed “Evolution of Cybercrime Intent & Hunting with YARA for Malware Developers” and was joined by a host of other presenters discussing best practices, free tools, and new strategies for effectively using YARA. A full agenda from the event as well as presentation recordings from the REVERSING 2020 summit will be available on ReversingLabs YouTube channel and website starting the week of July 6.

For more information on how to use these YARA rules within ReversingLabs Titanium Platform, see “Level Up Your YARA Game” by Tomislav Pericin on the ReversingLabs blog or “How to Hunt for Threats Using YARA Rules,” an instructional video for the ReversingLabs Titanium Platform and A1000 by analyst Robert Perica.

About ReversingLabs

ReversingLabs is the leading provider of explainable threat intelligence solutions that shed the necessary light on complex file-based threats for enterprises stretched for time and expertise. Its hybrid-cloud Titanium Platform enables digital business resiliency, protects against new modern architecture exposures, and automates manual SOC and Threat Hunting processes with a transparency that arms junior analysts to confidently take action.

ReversingLabs is used by the world’s most advanced security vendors and deployed across all industries searching for a more intelligent way to get at the root of the web, mobile, email, cloud, app development and supply chain threat problem, of which files and objects have become major risk contributors.

ReversingLabs Titanium Platform provides broad integration support with more than 4,000 unique file and object formats, speeds detection of malicious objects through automated static analysis, prioritizing the highest risks with actionable detail in only .005 seconds. With unmatched breadth and privacy, the platform accurately detects threats through explainable machine learning models, leveraging the largest repository of malware in the industry, containing more than 10 billion files and objects. Delivering transparency and trust, thousands of ‘human readable’ indicators explain why a classification and threat verdict was determined, while integrating at scale across the enterprise with connectors that support existing file repository, SIEM, SOAR, threat intelligence platform and sandbox investments, reducing incident response time for SOC analysts, while providing high priority and detailed threat information for both developers and hunters to take quick action.

Learn more at https://www.reversinglabs.com, or connect on LinkedIn or Twitter.

###

Media Contact:
Jennifer Balinski, Guyer Group
Jennifer.balinski@guyergroup.com

More Press Releases

ReversingLabs Expert Personnel Join Global Cyber Defense Teams at NATO’s CCDCOE Locked Shields

ReversingLabs Expert Personnel Join Global Cyber Defense Teams at NATO’s CCDCOE Locked Shields

Participants Leverage ReversingLabs Spectra Platform in World’s Largest Cyber Defense Exercise

Learn More about ReversingLabs Expert Personnel Join Global Cyber Defense Teams at NATO’s CCDCOE Locked Shields
ReversingLabs Expert Personnel Join Global Cyber Defense Teams at NATO’s CCDCOE Locked Shields
RL Honors Press Release

ReversingLabs Spectra Assure Earns Multiple Top Honors for Leading Software Supply Chain Security Solution

Company Insights on Software Supply Chain Security and Threat Intelligence Featured in New Enterprise AI Security Handbook Published by TAG Infosphere

Learn More about ReversingLabs Spectra Assure Earns Multiple Top Honors for Leading Software Supply Chain Security Solution
ReversingLabs Spectra Assure Earns Multiple Top Honors for Leading Software Supply Chain Security Solution
ReversingLabs Named Winner of the Global InfoSec Awards During RSAC Conference 2026

ReversingLabs Named Winner of the Global InfoSec Awards During RSAC Conference 2026

ReversingLabs Spectra Assure® Named Groundbreaking Software Supply Chain Security Solution

Learn More about ReversingLabs Named Winner of the Global InfoSec Awards During RSAC Conference 2026
ReversingLabs Named Winner of the Global InfoSec Awards During RSAC Conference 2026

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu