Paranoya is a command-line IOC and YARA scanner for identifying suspicious and malicious files. It is a fork of Loki that has been rewritten and extended with additional scanning capabilities. The software is designed around indicator-based malware detection and can examine either individual files or complete directory trees.
The scanner combines indicators of compromise with YARA rules from several security-focused sources. These include rule collections used for identifying malware families, phishing kits and other suspicious content. Paranoya can therefore use both file characteristics and signature-based rules when assessing material presented for analysis.
Paranoya can also operate as a persistent scanning daemon. An accompanying client submits files or paths to the scanner, allowing it to be integrated into automated security workflows without starting a new scanning process for every request. Listening addresses, ports, output behaviour and logging can be adjusted through command-line options.
An intensive scanning mode enables additional checks when a more thorough examination is needed. The software also provides configurable output and can produce CSV results for further processing. Its rule-based design allows detection coverage to evolve as new YARA signatures and indicators are introduced, while the project continues to receive maintenance and security-related updates.
This is free and open source software.
Key Features
- Scans files for indicators of compromise.
- Uses YARA rules for malware detection.
- Scans individual files.
- Scans complete directory trees.
- Uses multiple security-focused rule collections.
- Provides an intensive scanning mode.
- Runs as a persistent scanning daemon.
- Includes a client for submitting scan requests.
- Supports configurable listening addresses and ports.
- Provides configurable logging.
- Supports CSV output.
- Integrates with automated security workflows.
Website: github.com/c0m4r/paranoya
Support:
Developer: c0m4r
License: GNU General Public License v3.0
Paranoya is written in Python. Learn Python with our recommended free books and free tutorials.
Related Software
| Anti-Malware Tools | |
|---|---|
| ClamAV | Antivirus engine for detecting trojans, viruses, malware and other threats |
| YARA-X | Re-incarnation of YARA |
| YARA | Pattern matching swiss knife for malware researchers |
| Maltrail | Malicious traffic detection system |
| ClamTk | Graphical frontend for ClamAV |
| LMD | Malware scanner focusing on threats faced in shared hosted environments |
| phpMussel | PHP-based anti-virus anti-trojan anti-malware solution |
| Raspirus | Lightweight signature-based malware scanner |
| FastFinder | Fast suspicious file finder |
| Rootkit Hunter | Scans for rootkits, backdoors and possible local exploits |
| Unhide | Forensic tool to find hidden processes and TCP/UDP ports |
| Hostsblock | Malware-blocking cronscript |
| libredefender | Antivirus program using libclamav |
| Lenspect | Lightweight security threat scanner |
| chkrootkit | Locally checks for signs of a rootkit |
Read our verdict in the software roundup.
Explore our carefully curated directory of recommended free and open source software, covering every major software category.The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more. Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form. |


Please read our Comment Policy before commenting.