One rule, past and future
Scan parsed HTTP response bodies for phishing kits, injected JavaScript, credential harvesters, and other malicious web content. Write the rule, test it against sample content, and run it at scale.
The same rule works in both directions. Run it back across the history we have already collected to see everywhere the pattern has appeared, and forward against new telemetry so future matches surface on their own.
- Standard YARA, with full support for YARA-X
- Retrohunt across collected history, monitor against new collection
- Every match opens the full HTTP event behind it
- Rules live in a Project, alongside the rest of the investigation
Weeks of new matches against one standing rule, including the weeks it stayed quiet.