Skip to content

YARA

Pattern matching tool for identifying and classifying malware with rules that describe strings, byte patterns, and conditions.

When I Use It

  • Searching a folder, disk image, or memory capture for files that match known malware families
  • Turning what I learned from one sample into a rule that finds related samples elsewhere
  • Checking threat intel rules from vendors and researchers against my own environment

Installation

  • Debian / Ubuntu: sudo apt install yara
  • Windows: download the latest release from https://github.com/VirusTotal/yara/releases
  • Build from source: install automake libtool make gcc pkg-config, extract the release, then run ./bootstrap.sh, ./configure, make, and sudo make install
  • Confirm the installation: yara --version

YARA-X, VirusTotal's Rust rewrite of YARA, is the successor project and runs most existing rules.

Common Tasks

Run Rules

Task Command
Scan a file or folder yara rules.yar /path/to/target
Scan subfolders recursively yara -r rules.yar /path/to/target
Show the matching strings yara -s rules.yar file.exe
Show rule metadata yara -m rules.yar file.exe
Scan memory with Volatility vol -f memdump.mem yarascan.YaraScan --yara-file rules.yar

Write a Rule

rule Suspicious_PowerShell_Download
{
    meta:
        description = "PowerShell download cradle strings"
        author = "EvolvingSysadmin"
    strings:
        $a = "DownloadString" ascii wide nocase
        $b = "IEX" ascii wide
        $c = "Net.WebClient" ascii wide nocase
    condition:
        2 of them
}
Section Purpose
meta Description, author, date, references
strings Text, hex, or regular expression patterns; modifiers like ascii, wide, and nocase
condition Logic that decides a match, for example 2 of them, all of them, or uint16(0) == 0x5A4D for files starting with MZ

Generate Rules with yarGen

yarGen builds rules from strings in malware samples, filtered against a database of strings from legitimate software.

Step Command
Install requirements pip install -r requirements.txt
Download the goodware databases python3 yarGen.py --update
Generate rules for a folder of samples python3 yarGen.py -m /path/to/malware -o ./rules.yar

Reading the Output

  • Each match prints the rule name and the file; -s adds the offset and value of each matching string
  • Generated rules from yarGen almost always need tuning: remove strings that are common in legitimate software and tighten the condition
  • Test new rules against a set of clean files before using them widely, to catch false positives

Resources