
新发布Aug 19, 2026
yara v4.5.8
模式匹配的瑞士军刀
[!IMPORTANT] 此项目处于维护模式。更多信息:https://virustotal.github.io/yara-x/blog/yara-x-is-stable/
YARA 简介
YARA 是一款旨在(但不限于)帮助恶意软件研究人员识别和分类恶意软件样本的工具。使用 YARA,你可以基于文本或二进制模式创建对恶意软件家族(或任何你想描述的事物)的描述。每个描述,即所谓的规则,由一组字符串和一个决定其逻辑的布尔表达式组成。让我们看一个例子:
rule silent_banker : banker
{
meta:
description = "This is just an example"
threat_level = 3
in_the_wild = true
strings:
$a = {6A 40 68 00 30 00 00 6A 14 8D 91}
$b = {8D 4D B0 2B C1 83 C0 27 99 6A 4E 59 F7 F9}
$c = "UVODFRYSIHLNWPEJXQZAKCBGMT"
condition:
$a or $b or $c
}
上面的规则告诉 YARA,任何包含这三个字符串之一的文件都必须被报告为 silent_banker。这只是一个简单的例子,通过使用通配符、不区分大小写的字符串、正则表达式、特殊运算符以及许多其他功能,可以创建更复杂、更强大的规则,这些功能在 YARA 的文档 中有详细说明。
YARA 是跨平台的,可在 Windows、Linux 和 Mac OS X 上运行,既可以通过其命令行界面使用,也可以通过 yara-python 扩展从你自己的 Python 脚本中使用。
附加资源
你是否使用 GitHub 来存储你的 YARA 规则?YARA-CI 可能是一个有用的补充工具。这是一个 GitHub 应用程序,为你的规则提供持续测试,帮助你识别常见错误和误报。
如果你计划使用 YARA 扫描压缩文件(.zip、.tar 等),你应该了解一下 yextend,这是 Bayshore Networks 开发和开源的一个非常有用的 YARA 扩展。
此外,来自 InQuest 的朋友们整理了一份很棒的 YARA 相关资料列表。
谁在使用 YARA
- 0x101 Cyber Security
- Adlice
- AlienVault
- Avast
- BAE Systems
- Bayshore Networks, Inc.
- Binalyze
- BinaryAlert
- Blueliv
- Cado Security
- Cisco Talos Intelligence Group
- Cloudina Security
- Cofense
- Conix
- Corelight
- CounterCraft
- Cuckoo Sandbox
- Cyber Triage
- Cybereason
- Digita Security
- Dragos Platform
- Dtex Systems
- ESET
- ESTsecurity
- Elastic Security
- FactorX.ai
- Fidelis XPS
- FireEye, Inc.
- Forcepoint
- Fox-IT
- FSF
- Guidance Software
- Heroku
- Hornetsecurity
- ICS Defense
- InQuest
- IntelOwl
- Joe Security
- Kaspersky Lab
- KnowBe4
- Koodous
- Laika BOSS
- Lastline, Inc.
- libguestfs
- LimaCharlie
- Malpedia
- Malwation
- McAfee Advanced Threat Defense
- Metaflows
- NBS System
- ndaal
- NetLock
- Nextron Systems
- Nozomi Networks
- osquery
- Payload Security
- PhishMe
- Picus Security
- Radare2
- RedSocks Security
- ReversingLabs
- Scanii
- SecondWrite
- SonicWall
- SpamStopsHere
- Spyre
- stoQ
- Sublime Security
- SumoLogic
- Tanium
- Tenable Network Security
- Tenzir
- The DigiTrust Group
- ThreatConnect
- ThreatStream, Inc.
- Thug
- Threat.Zone
- TouchWeb
- Trend Micro
- UnpacMe
- UpSight Security Inc.
- Uptycs Inc
- Veeam
- Verisys Antivirus API
- VirusTotal Intelligence
- VMRay
- Volexity
- We Watch Your Website
- x64dbg
- YALIH
你是否在使用它?希望你的网站出现在这里吗?