logo

YAMAGoya: A Real-time Client Monitoring Tool Using Sigma and YARA Rules

ID: 7f97ed9b-01a8-5029-b84e-5e8c0b46ce9f

STIX ID: report--7f97ed9b-01a8-5029-b84e-5e8c0b46ce9f

Feed Name: JPCERT Blog

Date Published: 2025-11-18

Date Updated: 2026-04-19

Author: 朝長 秀誠 (Shusei Tomonaga)

...
...

This blog introduces YAMAGoya, an open-source Windows threat hunting tool that combines real-time ETW event monitoring with YARA memory scanning, supports Sigma and custom YAML correlation rules, and offers both GUI/CLI operation. It outlines installation and usage, describes supported event targets and correlation logic, details logging and Windows Event Log IDs for alerts, and provides an FAQ, positioning YAMAGoya as a complementary tool to leverage community detection rules for threat hunting and incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.