YARA
YARA is a pattern-matching tool used to identify and classify malware samples for malware researchers, and it is free under the BSD 3-Clause license.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
What it is
Rules name text or byte patterns and a condition, and YARA reports the files that meet that condition. People run it on Windows, Linux, and Mac, from the command line or its Python library.
What it helps with
- Finding files that contain the strings or bytes a rule describes
- Classifying a sample when the rule's condition is met
- Scanning a file, a folder, or a process without a custom parser
Who it's for
Malware researchers and detection engineers who keep a rule set and need a local way to sort samples. It classifies files. It is not a sandbox.
Worth knowing
The official README says YARA is in maintenance mode and points readers to YARA-X.
What does a rule match?
It matches when the described text or bytes are present and the rule's condition is true.
What does it cost?
Nothing. It is free under the BSD 3-Clause license.
Who maintains it?
The VirusTotal project maintains it, and the repo is public.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.