mkYARA Logo

mkYARA

0
Free
Updated 11 March 2025
Visit Website

Writing YARA rules based on executable code within malware can be a tedious task. An analyst cannot simply copy and paste raw executable code into a YARA rule, because this code contains variable values, such as memory addresses and offsets. The analyst has to disassemble the code and wildcard all the pieces in the code that can change between samples. mkYARA aims to automate this part of writing rules by generating executable code signatures that wildcard all these little pieces of executable code that are not static. Installation is as easy as installing the pip package. pip install mkyara Usage: import codecs from capstone import CS_ARCH_X86, CS_MODE_32 from mkyara import YaraGenerator gen = YaraGenerator("normal", CS_ARCH_X86, CS_MODE_32) gen.add_chunk(b"\x90\x90\x90", offset=1000) gen.add_chunk(codecs.decode("6830800000E896FEFFFFC3", "hex"), offset=0x100) gen.add_chunk(b"\x90\x90\x90\xFF\xD7", is_data=True) rule = gen.generate_rule() rule_str = rule.get_rule_string() print(rule_str) Standalone Tool: mkYARA comes with a standalone tool that is cross platform, as in, it can create signatures for Windows binaries running under Linux. Usage: mkyara [-h] [-i {x86}

FEATURES

SIMILAR TOOLS

Fuzzilli is a JavaScript engine fuzzer that helps identify vulnerabilities in JavaScript engines.

YARA is a tool for identifying and classifying malware samples based on textual or binary patterns.

Generates a YARA rule to match basic blocks of the current function in IDA Pro

A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.

A strings statistics calculator for YARA rules to aid malware research.

A tool that generates pseudo-malicious files to trigger YARA rules.

A blog post discussing INF-SCT fetch and execute techniques for bypass, evasion, and persistence

Automated Android Malware Analysis tool

A tool for deep analysis of malicious files using ClamAV and YARA rules, with features like scoring suspect files, building visual tree graphs, and extracting specific patterns.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved