YARA-X
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Next-generation YARA engine rewritten in Rust. Faster, safer, and more reliable than legacy YARA with full rule compatibility.
INSTALLATION#
# Cargo (Rust) cargo install yara-x-cli # Or download from: https://github.com/VirusTotal/yara-x/releases # Python bindings pip install yara-x
BASIC USAGE#
# Scan file with rules yr scan rules.yar /path/to/file # Scan directory yr scan rules.yar /path/to/directory/ # Scan with multiple rule files yr scan rules1.yar rules2.yar /path/to/scan # Scan from stdin cat suspicious.exe | yr scan rules.yar - # Compile rules (check syntax) yr compile rules.yar # Debug/check rules yr check rules.yar # Dump module data yr dump /path/to/file
OUTPUT OPTIONS#
yr scan rules.yar file --output-format json # JSON output yr scan rules.yar file --output-format text # Text (default) yr scan rules.yar file --negate # Show non-matching files yr scan rules.yar file --count # Count matches only yr scan rules.yar file --print-strings # Show matched strings yr scan rules.yar file --print-namespace # Show rule namespace
RULE SYNTAX#
rule Example_Rule {
meta:
description = "Example YARA-X rule"
author = "Analyst"
date = "2024-01-01"
severity = "high"
reference = "https://example.com"
strings:
$text1 = "malicious string" ascii
$text2 = "another string" wide
$hex1 = { 4D 5A 90 00 } // MZ header
$regex1 = /https?:\/\/[a-z0-9.]+/ // URL pattern
condition:
uint16(0) == 0x5A4D and // PE file
filesize < 5MB and
2 of ($text*) and
$hex1
}
# String modifiers
$s = "text" ascii # ASCII encoding
$s = "text" wide # UTF-16 LE
$s = "text" nocase # Case insensitive
$s = "text" fullword # Word boundary match
$s = "text" xor # XOR encoded
$s = "text" base64 # Base64 encoded
$s = "text" base64wide # Base64 wide
# Hex patterns
$h = { 4D 5A [0-100] 50 45 } # MZ...PE with gap
$h = { 4D 5A ?? ?? 00 } # Wildcards
$h = { 4D ( 5A | 5B ) 90 } # Alternatives
# Condition operators
all of them # All strings match
any of them # Any string matches
2 of ($s*) # At least 2 match
$s1 and $s2 # Both match
$s1 or $s2 # Either matches
$s1 at 0 # At specific offset
$s1 in (0..1024) # Within range
#s1 > 5 # Count of matches
YARA-X vs YARA (LEGACY)#
Feature YARA-X YARA (Legacy) ------- ------ ------------- Language Rust C Speed Faster Standard Memory safety Yes Manual Rule compat 99%+ compatible Full Modules PE, ELF, etc. PE, ELF, etc. Python bindings Yes Yes Active develop Yes Maintenance
PYTHON API#
import yara_x
# Compile rules
rules = yara_x.compile('rule test { strings: $a = "malware" condition: $a }')
# Scan bytes
results = rules.scan(b"this contains malware")
for rule in results.matching_rules:
print(f"Matched: {rule.identifier}")
# Scan file
results = rules.scan(open("suspect.exe", "rb").read())
TIPS#
- Drop-in replacement for legacy YARA in most cases - Rust rewrite eliminates memory safety bugs - yr check validates rules before scanning - Use --print-strings to see what matched and where - Base64 and XOR modifiers catch encoded strings - Combine with Loki/Thor for endpoint scanning - VirusTotal uses YARA-X internally - Modules (PE, ELF, dotnet) provide structured file analysis - Custom rules complement community rule sets - JSON output for SIEM/automation integration