Skip to main content

A Python package and command line utility for scanning emails with YARA rules

Project description

yaramail logo

yaramail

Python tests PyPI PyPI - Downloads

yaramail is a Python package and command line utility for scanning emails with YARA rules. It is ideal for automated triage of phishing reports.

CLI Demo

asciicast

Features

  • Scans all parts of an email via API or CLI
    • Headers
      • Removes header indents by default for consistent scanning
    • Plain text and HTML body content
      • Converts body content to Markdown by default for consistent scanning
    • Attachments
      • Raw file content
      • Emails attached to emails
      • PDF document text
      • ZIP file contents, including nested ZIP files
        • Uses message body content as a list of possible ZIP passwords
        • Customizable list of passwords to use when attempting to scan encrypted ZIP files
  • Provides a built-in methodology for categorizing emails
  • Parses Authentication-Results headers

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

yara_mail-3.4.0.tar.gz (14.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

yara_mail-3.4.0-py3-none-any.whl (15.5 kB view details)

Uploaded Python 3

File details

Details for the file yara_mail-3.4.0.tar.gz.

File metadata

  • Download URL: yara_mail-3.4.0.tar.gz
  • Upload date:
  • Size: 14.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: Hatch/1.16.5 cpython/3.13.9 HTTPX/0.28.1

File hashes

Hashes for yara_mail-3.4.0.tar.gz
Algorithm Hash digest
SHA256 f9f53a88fbb4dd2bfa76ac569871a37f38be1d20091fc46c0267cdbc473a03e4
MD5 3311085453fa38cf8253c43128839bda
BLAKE2b-256 732f288d63368a0bcbd3c6f94790850bc104c13a625b649a27e2fcf0598f6d1a

See more details on using hashes here.

File details

Details for the file yara_mail-3.4.0-py3-none-any.whl.

File metadata

  • Download URL: yara_mail-3.4.0-py3-none-any.whl
  • Upload date:
  • Size: 15.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: Hatch/1.16.5 cpython/3.13.9 HTTPX/0.28.1

File hashes

Hashes for yara_mail-3.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 34966a28326ec77b27b0430e276371f4f270dd99bb2abf75add04c7baa83ead0
MD5 bb48ceaf325f31de5810ad801c43ed1f
BLAKE2b-256 2da133e82917f7697d8ea774ac15ae3b67b753eb96a661389074a1e8317313d2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page