Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
yaraast — A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation | Kitploit
Tools/GitHubGitHub/seifreed/yaraast
Static AnalysisVulnerability AnalysisCode AnalysisScripting & AutomationMalware AnalysisUtilities & Frameworks
GitHubseifreed/yaraast

yaraast

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

View Repository
5451 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

YARAAST

yaraast

Parse, analyze, and transform YARA rules with a Python AST toolkit

CI License: MIT Python 3.11-3.14

GitHub Stars GitHub Issues Docs


Overview

yaraast is a Python library for parsing and manipulating YARA-family rules using Abstract Syntax Trees (AST). It supports classic YARA, YARA-L, and YARA-X workflows with automatic dialect detection and CLI tooling.

Key Features

FeatureDescription
Multi-dialect ParsingParse YARA, YARA-L, and YARA-X from files or strings
Automatic Dialect DetectionUnified parser auto-detects rule dialects
AST ToolingBuild, transform, diff, and serialize ASTs
Formatting & ValidationCLI commands for parse/format/validate workflows
Streaming SupportParse very large files with streaming mode
Ecosystem IntegrationsOptional LSP and libyara-related capabilities

Supported Rule Ecosystem

root@kitploit:~
Dialects   YARA, YARA-L, YARA-X
Parsers    Standard parser, unified parser, streaming parser
Outputs    YARA, JSON, YAML, AST tree views
Tooling    CLI, visitors, builders, serialization, semantic checks

Support levels differ by dialect. Classic YARA is stable, YARA-X is beta, YARA-L is experimental, and automatic dialect detection is best effort. See the compatibility matrix for the exact engines and capabilities exercised by CI.


Installation

From PyPI (Recommended)

root@kitploit:~
pip install yaraast

From Source

root@kitploit:~
git clone https://github.com/seifreed/yaraast.git
cd yaraast
python3 -m venv venv
source venv/bin/activate  # Windows: venv\Scripts\activate
pip install -e .

Quick Start

root@kitploit:~
import yaraast

yara_code = """
rule example {
    strings:
        $a = "malware" nocase
    condition:
        $a
}
"""

document = yaraast.parse(yara_code)
print(document.ast.rules[0].name)

Usage

Command Line Interface

root@kitploit:~
# Parse and print normalized YARA
yaraast parse rules.yar

# Parse to JSON
yaraast parse rules.yar --format json

# Parse with explicit dialect
yaraast parse rules.yar --dialect yara-x

# Validate file (syntax + parse checks)
yaraast validate rules.yar

# Format file in-place (AST-based formatter)
yaraast fmt rules.yar

# Check formatting without modifying file
yaraast fmt rules.yar --check

Core CLI Commands

CommandDescription
parseParse a rule file and output YARA/JSON/YAML/tree
validateValidate rules and run validation subcommands
fmtAST-based formatter (with --check and --diff)
formatFormat input into a target output file
validate-syntaxSyntax-focused validation entrypoint
lspLaunch Language Server Protocol features

Python Library

Unified Parsing

root@kitploit:~
from pathlib import Path

import yaraast

source = "rule example { condition: true }"

# Auto-detect dialect
document = yaraast.parse(source)

# Force specific dialect
document = yaraast.parse(source, dialect="yara")

# Parse files, generate new source, and format canonically
Path("rules.yar").write_text(source, encoding="utf-8")
file_document = yaraast.parse_file("rules.yar")
generated = yaraast.generate(file_document)
formatted = yaraast.format_canonical(source, dialect="yara")

# Preserve every byte outside an explicit UTF-8 byte edit
offset = source.encode("utf-8").index(b"true")
rewritten = yaraast.rewrite_lossless(
    source,
    [yaraast.SourceEdit(offset, offset + 4, "false")],
)

# Public parsers apply bounded defaults. Override them per operation when needed.
limits = yaraast.ResourceLimits(max_input_bytes=1024 * 1024, parse_deadline=5.0)
document = yaraast.parse(source, resource_limits=limits)

cancel = yaraast.CancellationToken()
cancel.cancel()
# yaraast.parse(source, cancellation_token=cancel) raises ParseCancelledError

ResourceLimits() disables all bounds explicitly. CLI parsing uses the public defaults; LSP parsing uses tighter input, token, nesting, pattern, and deadline limits and never caches a partial result after cancellation or a limit failure.

Direct Parser + Visitor

root@kitploit:~
from pathlib import Path

from yaraast.parser import Parser
from yaraast.visitor import BaseVisitor

class RuleCollector(BaseVisitor):
    def __init__(self):
        self.rules = []

    def visit_rule(self, node):
        self.rules.append(node.name)
        super().visit_rule(node)

ast = Parser(Path("rules.yar").read_text(encoding="utf-8")).parse()
collector = RuleCollector()
collector.visit(ast)
print(collector.rules)

Optional Dependencies

root@kitploit:~
# LSP support
pip install yaraast[lsp]

# libyara integration
pip install yaraast[libyara]

# Performance tooling
pip install yaraast[performance]

# Visualization support
pip install yaraast[visualization]

# Runtime support bundle
pip install yaraast[all]

# Runtime and development tooling
pip install yaraast[dev-all]

Runtime Docs

  • Dialect compatibility: docs/compatibility.md
  • LSP runtime internals: docs/lsp-runtime.md
  • LSP parity report: docs/lsp-parity-report.md
  • Latest runtime benchmark artifact: docs/benchmarks/lsp-runtime-latest.json

Requirements

  • Python 3.11, 3.12, 3.13, or 3.14
  • See pyproject.toml for full dependency and extras list

Contributing

Contributions are welcome. See CONTRIBUTING.md for setup, quality checks, and workflow guidelines.

  1. Fork the repository
  2. Create a branch (git checkout -b feature/your-change)
  3. Commit changes (git commit -m "Add your change")
  4. Push (git push origin feature/your-change)
  5. Open a Pull Request

Project policy is documented in SECURITY.md, CODE_OF_CONDUCT.md, CHANGELOG.md, and MIGRATING.md.


License

This project is licensed under the MIT License - see LICENSE.

Author

  • Marc Rivero ([email protected])
  • Repository: github.com/seifreed/yaraast

Built for malware analysis and detection engineering workflows

Download Tool