DETECTIONS · 52 artefacts
Deployable YARA, Sigma, Suricata, and IOC artefacts derived from OHIIHO research.
Download directly — no GitHub account required. Free to use with attribution.
CAMPAIGN PACKS
Full detection sets tied to a specific threat actor or campaign — YARA + Sigma + IOCs.
Hydra Bot v5
Redis Stager + P2PInfect
Read report →Sorry Worm / Diicot
Linux Ransomware + SSH Botnet
YARA: binary strings .yar
YARA: encrypted files .yar
Sigma: ransomware drop .yml
Sigma: loader cleanup .yml
Sigma: process masquerade .yml
IOCs: playbook CSV
IOCs: catching CSV
Read report →Watcher / NetAI-SKN
Dual-Stage Linux Loader
YARA: loader + SKN .yar
Sigma: process creation .yml
Sigma: C2 network .yml
Sigma: loader callback .yml
Sigma: systemd persistence .yml
IOCs CSV
Read report →CRIMEWARE ARSENAL — 27 YARA RULES
One YARA rule per crimeware tool recovered from live adversary sessions.
IOC FILES
Machine-readable indicator files from published reports.
Turf Wars: Diicot SSH BotnetCSV
Prometei Asia C2 — Linux SideCSV
Prometei Cross-Platform PivotCSV
Outlaw Syria RelayCSV
AsyncSSH Residential BotnetCSV
FortiBleed in the OpenCSV
FortiBleed — DefenseCSV
FortiBleed Detection BriefCSV
52 detection files across 18 reports. Packs grow as new reports are published. For rule updates or custom indicators, contact research@ohiiho.com.