Quick reminder: you can activate the full YARA-Forge rule sets in our free products THOR Lite and THOR Cloud Lite
Use the options shown below to select or download the rule package:
In THOR Cloud Lite:
select Yara Forge → core under Global Settings
In THOR Lite: run
./thor-lite-util yara-forge download --ruleset core
This enables the full YARA Forge rule set curated from Signature-Base, YARA-Forge, and other sources.
Blog: nextron-systems.com/2025/04/…
The SLAYSTYLE web shells (aka BEEFLUSH) from Mandiant’s report on BRICKSTORM (UNC5221, China-nexus) just surfaced on VirusTotal
If you’re already using the rules from Signature-Base or YARA-Forge, you’re covered
0 AV detection rate
Report
cloud.google.com/blog/topics…
Sample
virustotal.com/gui/file/92fb…
Nov 4, 2025 · 4:08 PM UTC











