YARA-X
YARA-X is a pattern-matching tool used to identify and classify malware samples for malware researchers, and it is free under the BSD 3-Clause license.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxmacOSWindows
- License
- Open source
What it is
YARA-X is a pattern-matching tool used to identify and classify malware samples for malware researchers, and it is free under the BSD 3-Clause license. It is a Rust rewrite meant to replace classic YARA. Prebuilt builds run on Linux, macOS, and Windows.
What it helps with
- Classifying files with text or byte patterns and a boolean condition
- Reusing most existing YARA rules without a rewrite
- Running locally from the command line or its Python library
Who it's for
Malware researchers and detection engineers who are moving off classic YARA or starting with the current project. It is a poor fit if you need to scan a running process.
Worth knowing
Most existing YARA rules work unchanged. The C, Python, and Go interfaces are not drop-in replacements. Process scanning is not implemented.
What does a rule match?
It matches when the described text or bytes are present and the rule's condition is true.
What does it cost?
Nothing. It is free under the BSD 3-Clause license.
Who maintains it?
VirusTotal maintains the public repo.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.