Actionable Threat Intel (IV) - YARA beyond files: extending rules to network IoCs
ID: 02e40e87-37e1-5aa3-bfb3-f80e8f74f478
STIX ID: report--02e40e87-37e1-5aa3-bfb3-f80e8f74f478
Feed Name: VirusTotal Blog
VirusTotal unveils YARA Netloc, extending YARA hunting to network entities (domains, URLs, IPs) via the vt.net attribute and Livehunt, with templates and community rules to accelerate adoption. The post showcases practical detections—monitoring domains distributing malware, flagging Cobalt Strike C2 by default SSL certificate thumbprint, and identifying Telegram-based exfiltration URLs linked to stealer activity—highlighting how to combine network signals with VirusTotal metadata for proactive infrastructure tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
