all options
wheezy-backports  ] [  jessie  ] [  stretch  ] [  sid  ]
[ Source: yara  ]

Package: yara (3.2.0-1)

Links for yara

Screenshot

Debian Resources:

Download Source Package yara:

Maintainers:

External Resources:

Similar packages:

help to identify and classify malwares

YARA is a tool aimed at helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families based on textual or binary patterns contained on samples of those families. Each description consists of a set of strings and a Boolean expression which determines its logic. This is useful in forensics analysis.

Complex and powerful rules can be created by using binary strings with wild-cards, case-insensitive text strings, special operators, regular expressions and many other features.

Are examples of the organizations and services using YARA:

 - VirusTotal Intelligence (https://www.virustotal.com/intelligence/)
 - jsunpack-n (http://jsunpack.jeek.org/)
 - We Watch Your Website (http://www.wewatchyourwebsite.com/)
 - FireEye, Inc. (http://www.fireeye.com)
 - Fidelis XPS (http://www.fidelissecurity.com/network-security-appliance/ \
   Fidelis-XPS)

The Volatility Framework is an example of the software that uses YARA.

Other Packages Related to yara

  • depends
  • recommends
  • suggests
  • enhances

Download yara

Download for all available architectures
Architecture Package Size Installed Size Files
alpha (unofficial port) 114.9 kB695.0 kB [list of files]
amd64 101.1 kB494.0 kB [list of files]
arm64 87.1 kB446.0 kB [list of files]
armel 90.2 kB464.0 kB [list of files]
armhf 88.1 kB352.0 kB [list of files]
hppa (unofficial port) 108.3 kB487.0 kB [list of files]
i386 108.3 kB489.0 kB [list of files]
kfreebsd-amd64 101.2 kB456.0 kB [list of files]
kfreebsd-i386 107.9 kB493.0 kB [list of files]
m68k (unofficial port) 82.7 kB376.0 kB [list of files]
mips 102.8 kB579.0 kB [list of files]
mipsel 104.0 kB535.0 kB [list of files]
powerpc 93.3 kB524.0 kB [list of files]
powerpcspe (unofficial port) 100.6 kB496.0 kB [list of files]
ppc64 (unofficial port) 94.7 kB571.0 kB [list of files]
ppc64el 93.4 kB505.0 kB [list of files]
s390x 99.3 kB550.0 kB [list of files]
sh4 (unofficial port) 105.4 kB412.0 kB [list of files]
sparc 95.3 kB518.0 kB [list of files]
sparc64 (unofficial port) 95.9 kB540.0 kB [list of files]
x32 (unofficial port) 102.2 kB477.0 kB [list of files]