Platform

YARA Rules

An environment for developing, testing, and executing YARA rules across global web infrastructure, and for linking those rules to threat-hunting Projects.

app.validin.com
How it works

One rule, past and future

Scan parsed HTTP response bodies for phishing kits, injected JavaScript, credential harvesters, and other malicious web content. Write the rule, test it against sample content, and run it at scale.

The same rule works in both directions. Run it back across the history we have already collected to see everywhere the pattern has appeared, and forward against new telemetry so future matches surface on their own.

  • Standard YARA, with full support for YARA-X
  • Retrohunt across collected history, monitor against new collection
  • Every match opens the full HTTP event behind it
  • Rules live in a Project, alongside the rest of the investigation
ONE SAVED FINGERPRINT · NEW MATCHES PER WEEK 4 W1 none W2 11 W3 2 W4 none W5 19 W6 7 W7 3 W8 WRITTEN ONCE, REVIEWED WHEN IT FIRES

Weeks of new matches against one standing rule, including the weeks it stayed quiet.

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company