You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
YARA-X is a re-incarnation of YARA, a
pattern matching tool designed with malware researchers in mind. This new
incarnation intends to be faster, safer and more user-friendly than its
predecessor. The ultimate goal of YARA-X is replacing YARA as the default
pattern matching tool for malware researchers.
With YARA-X you can create descriptions of malware families (or whatever you
want to describe) based on textual or binary patterns. Each description (a.k.a.
rule) consists of a set of patterns and a boolean expression which determine its
logic. Let’s see an example:
rulesilent_banker: banker{
meta:
description="This is just an example"threat_level=3in_the_wild=truestrings:$a= {6A4068003000006A148D91}$b= {8D4DB02BC183C027996A4E59F7F9}$c="UVODFRYSIHLNWPEJXQZAKCBGMT"condition:$aor$bor$c
}
The above rule is telling YARA-X that any file containing one of the three
patterns must be reported as silent_banker. This is just a simple example,
more complex and powerful rules can be created by using wild-cards,
case-insensitive strings, regular expressions, special operators and many other
features that you'll find explained in
the documentation.
Yes, it is. YARA is still being maintained, and future releases will include
bug fixes and minor features. However, don’t expect new large features or
modules. All efforts to enhance YARA, including the addition of new modules,
will now focus on YARA-X.
What's the current state of YARA-X?
YARA-X is already mature and stable. At VirusTotal, we have been running YARA-X
in production for a long time, scanning billions of files with tens of thousands
of rules, and addressing discrepancies and bugs. This means that YARA-X is already
battle-tested.
Please test YARA-X and don’t hesitate
to open an issue if you
find a bug or some feature that you want to see implemented.