YAMAGoya: A Real-time Client Monitoring Tool Using Sigma and YARA Rules
ID: 7f97ed9b-01a8-5029-b84e-5e8c0b46ce9f
STIX ID: report--7f97ed9b-01a8-5029-b84e-5e8c0b46ce9f
Feed Name: JPCERT Blog
This blog introduces YAMAGoya, an open-source Windows threat hunting tool that combines real-time ETW event monitoring with YARA memory scanning, supports Sigma and custom YAML correlation rules, and offers both GUI/CLI operation. It outlines installation and usage, describes supported event targets and correlation logic, details logging and Windows Event Log IDs for alerts, and provides an FAQ, positioning YAMAGoya as a complementary tool to leverage community detection rules for threat hunting and incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
