Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
quipu — A desktop workbench for writing, validating, compiling, and testing YARA rules. | Kitploit
Tools/GitHubGitHub/corelight/quipu
Defensive ToolsStatic AnalysisVulnerability AnalysisCode AnalysisMalware AnalysisDigital ForensicsUtilities & FrameworksThreat IntelligenceIncident Response
GitHubcorelight/quipu

quipu

A desktop workbench for writing, validating, compiling, and testing YARA rules.

1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

Quipu logo
Quipu

A desktop workbench for writing, validating, compiling, and testing YARA rules.

CI status CodeQL status

Quipu (pronounced “KEE-poo”) brings a project explorer, a YARA-aware editor, the YARA-X compiler, and focused scan results into one local application. It embeds both YARA-X and its language server, so you do not need a separate YARA installation.

[!IMPORTANT] Quipu is at MVP stage. The initial supported platform is 64-bit Linux; Windows and macOS support will follow.

Quipu showing a compiled YARA project and two matching scan results

Features

  • Open a folder of .yar and .yara files as a workspace, or start with a scratch rule.
  • Explore inferred or configured entrypoints, nested includes, external includes, and project problems.
  • Edit with Monaco syntax highlighting, completion, hover documentation, and live YARA-X diagnostics.
  • Compile a complete workspace, then scan typed text or a selected file.
  • Inspect matching rules, patterns, offsets, byte lengths, and highlighted bytes in a hex viewer.
  • Jump from diagnostics and matches directly to their source definitions.
  • Restore unchanged compiled rulesets from a bounded local cache.
  • Work from a set of small, self-contained example projects included with the application.

Rules and scan targets are processed locally. Quipu does not send their contents to a remote service.

Install on Linux

Linux x86-64 packages are published on the GitHub Releases page:

PackageBest forInstall or run
AppImagePortable use on supported distributionschmod +x Quipu_*.AppImage && ./Quipu_*.AppImage
.debUbuntu 22.04+ and Debian 12+sudo apt install ./Quipu_*.deb
.rpmRecent Fedora releasessudo dnf install ./Quipu-*.rpm

The .deb and .rpm packages use the system WebKitGTK runtime. If your distribution cannot satisfy that dependency, use the AppImage.

Quipu packages are not currently signed. Each release includes a SHA256SUMS file; download it beside the packages and verify the files you downloaded with:

sha256sum --ignore-missing --check SHA256SUMS

The checksums detect accidental corruption but are not an authenticated signature.

Quick start

  1. Start Quipu and choose File → Open Example… → Basic text match.
  2. Explore text_indicators.yar in the editor.
  3. Choose Rules → Compile Workspace or press Ctrl+Shift+B.
  4. Scan the prepared target with Rules → Scan Target or press Ctrl+Shift+Enter.
  5. Expand a match and select it to inspect the highlighted bytes.

The full guide is bundled with Quipu under Help → Documentation. Its source is also available in documentation/content.

Workspaces and quipu.toml

Without configuration, Quipu recursively discovers rule files and infers an entrypoint from each file that is not included by another file. Add a quipu.toml at the workspace root when you need explicit entrypoints, include directories, or exclusions:

schema = 1
entrypoints = ["main.yar"]
include_dirs = ["rules", "../shared-rules"]
exclude = ["fixtures/**", "vendor/legacy/**"]

See Workspaces and projects for the complete project model and manifest reference.

Build from source

Quipu currently targets Linux x86-64. A build needs:

  • Rust 1.93 or newer
  • Node.js 22.6 or newer
  • Zola 0.23
  • Git
  • the native libraries required by Tauri and WebKitGTK

On Debian or Ubuntu, install the native dependencies with:

sudo apt update
sudo apt install -y \
  build-essential \
  curl \
  file \
  libayatana-appindicator3-dev \
  libgtk-3-dev \
  librsvg2-dev \
  libssl-dev \
  libwebkit2gtk-4.1-dev \
  patchelf \
  rpm \
  wget

Then build all three Linux package formats:

git clone https://github.com/corelight/quipu.git
cd quipu/app
npm ci
npm run tauri -- build --bundles appimage,deb,rpm

Artifacts are written below app/src-tauri/target/release/bundle/. The first build can take a while because Cargo compiles YARA-X and its dependencies from source.

Develop and test

Install dependencies and start the development application:

cd app
npm ci
npm run tauri -- dev

Run the frontend unit tests, production frontend build, and Rust tests with:

cd app
npm test
npm run build

cd src-tauri
cargo test --locked

The native-menu acceptance suite has additional Linux display-server requirements. See test/README.md for its setup and usage.

Architecture

Quipu is a Tauri application with a vanilla TypeScript frontend and a Rust backend:

  • Vite bundles the frontend and Monaco editor into the application webview.
  • Tauri IPC connects the UI to workspace, filesystem, compilation, cache, and scanning services in Rust.
  • The YARA-X compiler and language server run in-process.
  • Zola builds an offline documentation site that is embedded in the app.
app/src/           TypeScript frontend
app/src-tauri/     Rust backend and desktop packaging
documentation/    Source for the bundled offline guide
examples/          Projects bundled with the application
test/ui/           Native-menu acceptance test harness

The application version is defined in app/package.json; Tauri reads that value when it names packages and reports the running version.

Current limitations

  • Only Linux x86-64 packages are supported initially.
  • Quipu scans one selected file or one text buffer at a time, not directories or batches.
  • New rules are created at the workspace root. Move and delete operations are performed outside Quipu.
  • A scratch rule can be compiled and scanned, but not saved or cached.

Contributing and security

Contributions are welcome. Read CONTRIBUTING.md before opening a pull request.

Please do not report security vulnerabilities in a public issue. Follow the private reporting process in SECURITY.md.

Acknowledgements

Quipu is built by Corelight and powered by YARA-X, Monaco Editor, and Tauri.

License

Quipu is distributed under the 3-clause BSD license. See LICENSE. Notices for software incorporated from third parties are in THIRD_PARTY_LICENSES.

Download Tool