YAMA-Yet Another Memory Analyzer for malware detection
ID: 4b5b9bcc-9bd2-5dd6-9cfe-c3848cee4261
STIX ID: report--4b5b9bcc-9bd2-5dd6-9cfe-c3848cee4261
Feed Name: JPCERT Blog
This article introduces JPCERT/CC’s YAMA, a portable Windows memory-scanning tool that applies custom YARA rules to live processes to help detect obfuscated and fileless malware across endpoints. It describes key features (no installation, JSON/text and Event Log output), how to build a custom scanner via GitHub Actions by committing YARA rules, and usage options for scanning all processes or specific PIDs, directing output to file shares, and installing an Event Log manifest—aimed at streamlining incident response when traditional antivirus misses threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
