YARA¶
Pattern matching tool for identifying and classifying malware with rules that describe strings, byte patterns, and conditions.
When I Use It¶
- Searching a folder, disk image, or memory capture for files that match known malware families
- Turning what I learned from one sample into a rule that finds related samples elsewhere
- Checking threat intel rules from vendors and researchers against my own environment
Installation¶
- Debian / Ubuntu:
sudo apt install yara - Windows: download the latest release from https://github.com/VirusTotal/yara/releases
- Build from source: install
automake libtool make gcc pkg-config, extract the release, then run./bootstrap.sh,./configure,make, andsudo make install - Confirm the installation:
yara --version
YARA-X, VirusTotal's Rust rewrite of YARA, is the successor project and runs most existing rules.
Common Tasks¶
Run Rules¶
| Task | Command |
|---|---|
| Scan a file or folder | yara rules.yar /path/to/target |
| Scan subfolders recursively | yara -r rules.yar /path/to/target |
| Show the matching strings | yara -s rules.yar file.exe |
| Show rule metadata | yara -m rules.yar file.exe |
| Scan memory with Volatility | vol -f memdump.mem yarascan.YaraScan --yara-file rules.yar |
Write a Rule¶
rule Suspicious_PowerShell_Download
{
meta:
description = "PowerShell download cradle strings"
author = "EvolvingSysadmin"
strings:
$a = "DownloadString" ascii wide nocase
$b = "IEX" ascii wide
$c = "Net.WebClient" ascii wide nocase
condition:
2 of them
}
| Section | Purpose |
|---|---|
meta |
Description, author, date, references |
strings |
Text, hex, or regular expression patterns; modifiers like ascii, wide, and nocase |
condition |
Logic that decides a match, for example 2 of them, all of them, or uint16(0) == 0x5A4D for files starting with MZ |
Generate Rules with yarGen¶
yarGen builds rules from strings in malware samples, filtered against a database of strings from legitimate software.
| Step | Command |
|---|---|
| Install requirements | pip install -r requirements.txt |
| Download the goodware databases | python3 yarGen.py --update |
| Generate rules for a folder of samples | python3 yarGen.py -m /path/to/malware -o ./rules.yar |
Reading the Output¶
- Each match prints the rule name and the file;
-sadds the offset and value of each matching string - Generated rules from yarGen almost always need tuning: remove strings that are common in legitimate software and tighten the condition
- Test new rules against a set of clean files before using them widely, to catch false positives
Related¶
- Endpoint Malware playbook
- Volatility