Skip to content
hackingtools.ai

YARA-X

YARA-X is a pattern-matching tool used to identify and classify malware samples for malware researchers, and it is free under the BSD 3-Clause license.

0

0 upvotes · 0 downvotes

No ratings yet

Pricing
Free
Platforms
LinuxmacOSWindows
License
Open source

What it is

YARA-X is a pattern-matching tool used to identify and classify malware samples for malware researchers, and it is free under the BSD 3-Clause license. It is a Rust rewrite meant to replace classic YARA. Prebuilt builds run on Linux, macOS, and Windows.

What it helps with

- Classifying files with text or byte patterns and a boolean condition
- Reusing most existing YARA rules without a rewrite
- Running locally from the command line or its Python library

Who it's for

Malware researchers and detection engineers who are moving off classic YARA or starting with the current project. It is a poor fit if you need to scan a running process.

Worth knowing

Most existing YARA rules work unchanged. The C, Python, and Go interfaces are not drop-in replacements. Process scanning is not implemented.

What does a rule match?
It matches when the described text or bytes are present and the rule's condition is true.

What does it cost?
Nothing. It is free under the BSD 3-Clause license.

Who maintains it?
VirusTotal maintains the public repo.

Discussion & reviews

0 comments

Your rating (optional)

0/4,000

No contributions yet. Be the first to review or comment.

← Back to directory