Yara (v1.0.16)

The pattern matching swiss knife for malware researchers.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Utilities

Indicator fields (5)

Indicator types (1)

Layouts (1)

Playbooks (1)

Scripts (2)

README

YARA

About YARA

YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a boolean expression which determine its logic.

Pack Contents

YARA Scan automation - Performs a YARA scan on the specified files.
YARA - File Scan playbook - A playbook to run YARA scan against uploaded file. To run the playbook, provide the YARA rule content and the entry ID of the file you intend to scan.