JPCERT releases YAMAGoya hunting tool
JPCERT/CC open-sourced YAMAGoya, a userland tool combining ETW monitoring and YARA memory scanning to run Sigma and custom detection rules.
JPCERT/CC has released YAMAGoya, an open-source real-time threat hunting tool that combines ETW (Event Tracing for Windows) event monitoring with YARA-based memory scanning. The tool operates entirely in userland without requiring a kernel driver, and supports Sigma rules, custom YAML correlation rules, and YARA signatures to detect fileless or obfuscated malware across files, processes, registry, DNS, network traffic, PowerShell, and WMI activity in real time.
The blog post is primarily a tool announcement and usage guide rather than a threat report. It includes a worked example custom YAML rule designed to detect the ANEL backdoor delivered via a malicious document, correlating file creation, process execution, DLL loading, and a specific C2 IP address within a 10-second window to demonstrate the tool's multi-event correlation capability.
JPCERT/CC notes the tool is not a replacement for antivirus/EDR, ships with no default detection rules (users must supply their own Sigma/YARA/YAML rules), and has no built-in countermeasure against ETW bypass techniques that advanced attackers may use to evade detection. The tool supports both GUI and CLI operation, can run in the background, and can forward logs to SIEMs via the Windows Event Log or text output.
Mentioned in this report
Source reporting: https://blogs.jpcert.or.jp/en/2025/11/YAMAGoya.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free