AutoYara Logo

AutoYara

AutoYara is a Java tool that automatically generates YARA rules from malware samples using biclustering algorithms to help analysts create detection rules for malware families.

70
Security Operations
Free
Visit website
0

AutoYara Description

AutoYara is a Java-based tool that implements an algorithm for automatic YARA rule generation using biclustering techniques. The tool analyzes input files belonging to a specific malware family and creates YARA rules from the provided samples. The tool can operate with as few as 2 sample files and aims to achieve low false positive rates in rule generation. It accepts individual files or entire folders as input, processing files recursively when a directory is provided. Multiple input sources can be specified using multiple -i arguments. AutoYara requires Java 11 or greater to run and outputs generated rules to the current directory by default. Users can customize the output location and filename using the --out parameter. The tool is designed to assist security analysts by automating rule creation for common malware families, allowing them to focus on more complex samples that require manual analysis. The implementation is based on research from the paper "Automatic Yara Rule Generation Using Biclustering" and is provided as research code without warranty or support. A pre-built binary is available for download from the project's release section.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →