โ† All cheat sheets

YARA-X

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Next-generation YARA engine rewritten in Rust. Faster, safer,
and more reliable than legacy YARA with full rule compatibility.

INSTALLATION#

# Cargo (Rust)
cargo install yara-x-cli

# Or download from: https://github.com/VirusTotal/yara-x/releases

# Python bindings
pip install yara-x

BASIC USAGE#

# Scan file with rules
yr scan rules.yar /path/to/file

# Scan directory
yr scan rules.yar /path/to/directory/

# Scan with multiple rule files
yr scan rules1.yar rules2.yar /path/to/scan

# Scan from stdin
cat suspicious.exe | yr scan rules.yar -

# Compile rules (check syntax)
yr compile rules.yar

# Debug/check rules
yr check rules.yar

# Dump module data
yr dump /path/to/file

OUTPUT OPTIONS#

yr scan rules.yar file --output-format json  # JSON output
yr scan rules.yar file --output-format text  # Text (default)
yr scan rules.yar file --negate              # Show non-matching files
yr scan rules.yar file --count               # Count matches only
yr scan rules.yar file --print-strings       # Show matched strings
yr scan rules.yar file --print-namespace     # Show rule namespace

RULE SYNTAX#

rule Example_Rule {
    meta:
        description = "Example YARA-X rule"
        author = "Analyst"
        date = "2024-01-01"
        severity = "high"
        reference = "https://example.com"

    strings:
        $text1 = "malicious string" ascii
        $text2 = "another string" wide
        $hex1 = { 4D 5A 90 00 }              // MZ header
        $regex1 = /https?:\/\/[a-z0-9.]+/    // URL pattern

    condition:
        uint16(0) == 0x5A4D and              // PE file
        filesize < 5MB and
        2 of ($text*) and
        $hex1
}

# String modifiers
$s = "text" ascii                            # ASCII encoding
$s = "text" wide                             # UTF-16 LE
$s = "text" nocase                           # Case insensitive
$s = "text" fullword                         # Word boundary match
$s = "text" xor                              # XOR encoded
$s = "text" base64                           # Base64 encoded
$s = "text" base64wide                       # Base64 wide

# Hex patterns
$h = { 4D 5A [0-100] 50 45 }               # MZ...PE with gap
$h = { 4D 5A ?? ?? 00 }                    # Wildcards
$h = { 4D ( 5A | 5B ) 90 }                 # Alternatives

# Condition operators
all of them                                  # All strings match
any of them                                  # Any string matches
2 of ($s*)                                   # At least 2 match
$s1 and $s2                                  # Both match
$s1 or $s2                                   # Either matches
$s1 at 0                                     # At specific offset
$s1 in (0..1024)                             # Within range
#s1 > 5                                      # Count of matches

YARA-X vs YARA (LEGACY)#

Feature          YARA-X          YARA (Legacy)
-------          ------          -------------
Language         Rust            C
Speed            Faster          Standard
Memory safety    Yes             Manual
Rule compat      99%+ compatible Full
Modules          PE, ELF, etc.   PE, ELF, etc.
Python bindings  Yes             Yes
Active develop   Yes             Maintenance

PYTHON API#

import yara_x

# Compile rules
rules = yara_x.compile('rule test { strings: $a = "malware" condition: $a }')

# Scan bytes
results = rules.scan(b"this contains malware")
for rule in results.matching_rules:
    print(f"Matched: {rule.identifier}")

# Scan file
results = rules.scan(open("suspect.exe", "rb").read())

TIPS#

  - Drop-in replacement for legacy YARA in most cases
  - Rust rewrite eliminates memory safety bugs
  - yr check validates rules before scanning
  - Use --print-strings to see what matched and where
  - Base64 and XOR modifiers catch encoded strings
  - Combine with Loki/Thor for endpoint scanning
  - VirusTotal uses YARA-X internally
  - Modules (PE, ELF, dotnet) provide structured file analysis
  - Custom rules complement community rule sets
  - JSON output for SIEM/automation integration