Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

YARAAST

yaraast

Parse, analyze, and transform YARA rules with a Python AST toolkit

CI License: MIT Python 3.11-3.14

GitHub Stars GitHub Issues Docs


Overview

yaraast is a Python library for parsing and manipulating YARA-family rules using Abstract Syntax Trees (AST). It supports classic YARA, YARA-L, and YARA-X workflows with automatic dialect detection and CLI tooling.

Key Features

Feature Description
Multi-dialect Parsing Parse YARA, YARA-L, and YARA-X from files or strings
Automatic Dialect Detection Unified parser auto-detects rule dialects
AST Tooling Build, transform, diff, and serialize ASTs
Formatting & Validation CLI commands for parse/format/validate workflows
Streaming Support Parse very large files with streaming mode
Ecosystem Integrations Optional LSP and libyara-related capabilities

Supported Rule Ecosystem

Dialects   YARA, YARA-L, YARA-X
Parsers    Standard parser, unified parser, streaming parser
Outputs    YARA, JSON, YAML, AST tree views
Tooling    CLI, visitors, builders, serialization, semantic checks

Support levels differ by dialect. Classic YARA is stable, YARA-X is beta, YARA-L is experimental, and automatic dialect detection is best effort. See the compatibility matrix for the exact engines and capabilities exercised by CI.


Installation

pip install yaraast

From Source

git clone https://github.com/seifreed/yaraast.git
cd yaraast
python3 -m venv venv
source venv/bin/activate  # Windows: venv\Scripts\activate
pip install -e .

Quick Start

import yaraast

yara_code = """
rule example {
    strings:
        $a = "malware" nocase
    condition:
        $a
}
"""

ast = yaraast.parse(yara_code)
print(ast.rules[0].name)

Usage

Command Line Interface

# Parse and print normalized YARA
yaraast parse rules.yar

# Parse to JSON
yaraast parse rules.yar --format json

# Parse with explicit dialect
yaraast parse rules.yar --dialect yara-x

# Validate file (syntax + parse checks)
yaraast validate rules.yar

# Format file in-place (AST-based formatter)
yaraast fmt rules.yar

# Check formatting without modifying file
yaraast fmt rules.yar --check

Core CLI Commands

Command Description
parse Parse a rule file and output YARA/JSON/YAML/tree
validate Validate rules and run validation subcommands
fmt AST-based formatter (with --check and --diff)
format Format input into a target output file
validate-syntax Syntax-focused validation entrypoint
lsp Launch Language Server Protocol features

Python Library

Unified Parsing

from pathlib import Path

import yaraast

source = "rule example { condition: true }"

# Auto-detect dialect
ast = yaraast.parse(source)

# Force specific dialect
ast = yaraast.parse(source, dialect="yara")

# Parse files, generate new source, and format canonically
Path("rules.yar").write_text(source, encoding="utf-8")
file_ast = yaraast.parse_file("rules.yar")
generated = yaraast.generate(file_ast, dialect="yara")
formatted = yaraast.format_canonical(source, dialect="yara")

# Preserve every byte outside an explicit UTF-8 byte edit
offset = source.encode("utf-8").index(b"true")
rewritten = yaraast.rewrite_lossless(
    source,
    [yaraast.SourceEdit(offset, offset + 4, "false")],
)

# Public parsers apply bounded defaults. Override them per operation when needed.
limits = yaraast.ResourceLimits(max_input_bytes=1024 * 1024, parse_deadline=5.0)
ast = yaraast.parse(source, resource_limits=limits)

cancel = yaraast.CancellationToken()
cancel.cancel()
# yaraast.parse(source, cancellation_token=cancel) raises ParseCancelledError

ResourceLimits() disables all bounds explicitly. CLI parsing uses the public defaults; LSP parsing uses tighter input, token, nesting, pattern, and deadline limits and never caches a partial result after cancellation or a limit failure.

Direct Parser + Visitor

from pathlib import Path

from yaraast.parser import Parser
from yaraast.visitor import BaseVisitor

class RuleCollector(BaseVisitor):
    def __init__(self):
        self.rules = []

    def visit_rule(self, node):
        self.rules.append(node.name)
        super().visit_rule(node)

ast = Parser(Path("rules.yar").read_text(encoding="utf-8")).parse()
collector = RuleCollector()
collector.visit(ast)
print(collector.rules)

Optional Dependencies

# LSP support
pip install yaraast[lsp]

# libyara integration
pip install yaraast[libyara]

# Performance tooling
pip install yaraast[performance]

# Visualization support
pip install yaraast[visualization]

# Runtime support bundle
pip install yaraast[all]

# Runtime and development tooling
pip install yaraast[dev-all]

Runtime Docs


Requirements

  • Python 3.11, 3.12, 3.13, or 3.14
  • See pyproject.toml for full dependency and extras list

Contributing

Contributions are welcome. See CONTRIBUTING.md for setup, quality checks, and workflow guidelines.

  1. Fork the repository
  2. Create a branch (git checkout -b feature/your-change)
  3. Commit changes (git commit -m "Add your change")
  4. Push (git push origin feature/your-change)
  5. Open a Pull Request

Project policy is documented in SECURITY.md, CODE_OF_CONDUCT.md, CHANGELOG.md, and MIGRATING.md.


License

This project is licensed under the MIT License - see LICENSE.

Author


Built for malware analysis and detection engineering workflows

Metadata

Release files for yaraast 2.0.1rc1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for yaraast 2.0.1rc1
File Size Uploaded
yaraast-2.0.1rc1.tar.gz 2.1 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for yaraast 2.0.1rc1
File Interpreter ABI Platform
yaraast-2.0.1rc1-py3-none-any.whl Python 3 none any Details

Total release size: 3.0 MB

Release files / yaraast-2.0.1rc1.tar.gz

Download URL yaraast-2.0.1rc1.tar.gz
Size 2.1 MB
Tags Source
SHA-256 checksum
How to use checksums
369ff08bc179a937bc1e94b2819c88a0bdd55a17bb4e89c82f5ad8c96336e119
BLAKE2b-256 checksum
How to use checksums
cc65757091894d9b7d20d36fa9cb3ce70e2b863f5e31243009f3823fa1fa1ea2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / yaraast-2.0.1rc1-py3-none-any.whl

Download URL yaraast-2.0.1rc1-py3-none-any.whl
Size 853.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1e6078c4e2842b49c44ffa3966a235aa91ed3dac9a437046ca42837300b705e1
BLAKE2b-256 checksum
How to use checksums
825df5eb0c065216fbf6b77613d66a4eb7352f49c4feed87cb00de17759fb842
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

2.1.0

2 release files

2.0.1

2 release files

This release

2.0.1rc1 This release

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.7

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page