Yara Scanner For IMAP Feeds and saved Streams Reads an smtp formatted email file or connects to IMAP/POP server, reads emails and extracts attachments. Scans attachments with chosen Yara rule file. Writes the results to a Report File. Deletes the tmp dir created. Usage: IMAP Feed: python yaraMail.py -e -o sampleReport.txt -i -u me@you.com -p password -f inbox sample.yar imap.gmail.com POP Feed: python yaraMail.py -e -o sampleReport.txt -w -u you@me.com -p password sample.yar pop3.live.com From File: python yaraMail.py -e -o sampleReport.txt sample.yar SampleMail.txt Reports: Here is an example of the report print out From: Kevin Breen email@email.com Subject: Subject Line Att Name: Name of attatch.ext Matched Rules: Rule_Name1 Rule_Name2 Misc: The Attachement extract also extracts any Body to the EMail in either text/plain or text/HTML format -The text body of the email is typically named as part-001.ksh (this is what python mime guesses the ext as) -The HTML Body of the text is typically named as part-002.html ToDo: -Add verbose output
Common questions about yaraMail including features, pricing, alternatives, and user reviews.
yaraMail is A Yara scanner for IMAP feeds and saved streams, extracting attachments and scanning them with chosen Yara rule files. It is a Email Security solution designed to help security teams with YARA.
yaraMail is a free Email Security tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/kevthehermit/yaraMail/ for download and installation instructions.
Popular alternatives to yaraMail include:
Compare all yaraMail alternatives at https://cybersectools.com/alternatives/yaramail
yaraMail is for security teams and organizations that need YARA. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Email Security tools can be found at https://cybersectools.com/categories/email-security
Head-to-head feature, pricing, and rating breakdowns.
Email security platform protecting against phishing, malware, and BEC attacks
Open-source detection rules for email attacks like BEC, phishing, and malware
AI-powered DMARC monitoring and email authentication security platform
Email threat protection for Microsoft 365 with advanced detection capabilities