Arya: The New Tailor-Made EICAR Using Yara
ID: d81bdc1c-9e47-5dd0-b125-e4501c4f5e00
STIX ID: report--d81bdc1c-9e47-5dd0-b125-e4501c4f5e00
Feed Name: Claroty Team82
This report presents Arya, a tool that parses YARA rules (via yaramod) and synthesizes pseudo‑malicious files containing strings, byte sequences, PE headers, and x86 code to deliberately trigger YARA, antivirus, and EDR detections for research, rule QA, and purple‑teaming. It describes Arya's architecture (AST traversal, mapping and placer components), supported features, limitations, and intended use for testing detection pipelines rather than describing an active cyber incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
