CLI tool for rapid Yara rule prototyping
Project description
ygrep
CLI tool for rapid Yara rule testing.
usage: ygrep.py [-h] [-l] [-n] [-a] [-m MODIFIER] [-b BYTES] [-s STRING] [path]
yara grep - cmdline string/byte search
positional arguments:
path search path (default: **)
optional arguments:
-h, --help show this help message and exit
-l, --quiet list matching filenames only (suppress normal output)
-n, --dry-run do not scan, compile rule only
-a, --any set condition to 'any of them' (default: 'all of them')
-m MODIFIER, --modifier MODIFIER
modifier for string patterns - e.g. ascii,wide,nocase,xor,base64,base64wide
-b BYTES, --bytes BYTES
bytes to grep
-s STRING, --string STRING
string to grep
Example:
>>> ygrep -s "InternetConnectA" -s "WinHttpConnect" -a -m "xor"
rule x {
strings:
$s0 = "InternetConnectA" xor
$s1 = "WinHttpConnect" xor
condition:
any of them
}
extracted\api.VirtualAlloc.0x504000.mem
-------- ------------------- -----------------------------------------------
0x229d5c b'InternetConnectA' 49 6e 74 65 72 6e 65 74 43 6f 6e 6e 65 63 74 41
0x22ab1a b'WinHttpConnect' 57 69 6e 48 74 74 70 43 6f 6e 6e 65 63 74
-------- ------------------- -----------------------------------------------
extracted\api.VirtualAlloc.0x85000.mem
------- ------------------- -----------------------------------------------
0x28dcc b'InternetConnectA' 49 6e 74 65 72 6e 65 74 43 6f 6e 6e 65 63 74 41
------- ------------------- -----------------------------------------------
sdfmsdofpd
--- ---------------------------- -----------------------------------------------
0x8 b"\x1c;!0';0!\x16:;;06!\x14" 1c 3b 21 30 27 3b 30 21 16 3a 3b 3b 30 36 21 14
--- ---------------------------- -----------------------------------------------
>>> ygrep -b "AA ?? AA ?? BB" -s "kernel32"
rule x {
strings:
$s0 = "kernel32" ascii wide nocase
$b0 = { AA ?? AA ?? BB }
condition:
all of them
}
samples\tmp7v4jjmpn
--------- ----------------------- -----------------------
0x52f8 b'kernel32' 6b 65 72 6e 65 6c 33 32
0xe554 b'kernel32' 6b 65 72 6e 65 6c 33 32
0x27a08 b'kernel32' 6b 65 72 6e 65 6c 33 32
0x27c46 b'kernel32' 6b 65 72 6e 65 6c 33 32
0x27d34 b'kernel32' 6b 65 72 6e 65 6c 33 32
0x28578 b'kernel32' 6b 65 72 6e 65 6c 33 32
0x5a91c b'KERNEL32' 4b 45 52 4e 45 4c 33 32
0xa5224 b'KERNEL32' 4b 45 52 4e 45 4c 33 32
0xf50ac b'KERNEL32' 4b 45 52 4e 45 4c 33 32
0x102a00 b'KERNEL32' 4b 45 52 4e 45 4c 33 32
0x1137bf0 b'\xaa\xb4\xaa\xa3\xbb' aa b4 aa a3 bb
0x151c6a2 b'\xaa\x7f\xaa\xfe\xbb' aa 7f aa fe bb
--------- ----------------------- -----------------------
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
yara_grep-0.1.0.tar.gz
(2.8 kB
view details)
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file yara_grep-0.1.0.tar.gz.
File metadata
- Download URL: yara_grep-0.1.0.tar.gz
- Upload date:
- Size: 2.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.3 CPython/3.10.11 Windows/10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5884777dcdc9e0fcf74f38918bf3b4d316f61b6be75fabf9523ef9396cf898ba
|
|
| MD5 |
536be8f1b74e502e91e3b1ed5a47f7ca
|
|
| BLAKE2b-256 |
28d80e6da373afb60a5c43e2a7897c51c386c5143251448d03aca8f703769436
|
File details
Details for the file yara_grep-0.1.0-py3-none-any.whl.
File metadata
- Download URL: yara_grep-0.1.0-py3-none-any.whl
- Upload date:
- Size: 3.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.3 CPython/3.10.11 Windows/10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
888bd574a446f6db57306d4422b27449cfadca90a58aa46f07a39d4cf00eda4a
|
|
| MD5 |
3a23dbc8252ad9eeef37f582a44b6d9e
|
|
| BLAKE2b-256 |
75e304d44ea169dedbb9f60d6f83918527e13d5f9b92588c24623a2252a0a8d2
|