Skip to main content
# Overview

YaraTool was created to normalize yara signatures to format the signatures nicely, detect duplicates, and express a specific signature by hash (similar to how we express malware). The hashing method in this tool is the same as the Ruby Yara-Normalize module.

# Normalizing a signature

The following snippet takes a signature, normalizes it, prints out the pieces of the rule, and provides the "Yara Normalized" hash. The YNHash is designed to identify yara signatures.

import yaratool

if __name__ == "__main__":
ruletext = """rule DebuggerCheck__API : AntiDebug DebuggerCheck {
meta:
author="Some dude or dudette"
weight = 1
strings:
$ ="IsDebuggerPresent"
condition:
any of them
}"""
yr = yaratool.YaraRule(ruletext)
print yr.normalize()
print "Name: %s, Tags: %s, Author: %s" % (yr.name, "&".join(yr.tags), yr.metas['author'])
print "Strings: "
for string in yr.strings:
print " %s" % (string)
print "Condition: "
for condition in yr.condition:
print " %s" % (condition)
print yr.hash()

Outputs

rule DebuggerCheck__API : AntiDebug DebuggerCheck {
meta:
author = "Some dude or dudette"
weight = 1
strings:
$ = "IsDebuggerPresent"
condition:
any of them
}
Name: DebuggerCheck__API, Tags: AntiDebug&DebuggerCheck, Author: "Some dude or dudette"
Strings:
$ = "IsDebuggerPresent"
Condition:
any of them
yn01:d28d649e24c37244:d936fceffe

# Detecting Duplicate Rules

The following code iterates through all the files specified on the command line and counts the number of rules and duplicate rules. It will display the normalized versions of any duplicate rules.

import yaratool
import sys

if __name__ == "__main__":
count = 0
duplicates = 0
drf = yaratool.DuplicateDetector()
for filename in sys.argv[1:]:
fh = open(filename, 'r')
sigrules = fh.read()
fh.close()
rules = yaratool.split(sigrules)
for rule in rules:
ynhash = rule.hash()
res = drf.check(rule)
if res:
duplicates += 1
for r in res:
print r.normalize()
pass
print rule.normalize()
print
count += len(rules)
print "Count: %d, Duplicates: %d" % (count, duplicates)

Release files for yaratool 0.0.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for yaratool 0.0.7
File Size Uploaded
yaratool-0.0.7.tar.gz 6.4 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for yaratool 0.0.7
File Interpreter ABI Platform
yaratool-0.0.7-py3-none-any.whl Python 3 none any Details
yaratool-0.0.7-py2-none-any.whl Python 2 none any Details

Total release size: 23.3 kB

Release files / yaratool-0.0.7.tar.gz

Download URL yaratool-0.0.7.tar.gz
Size 6.4 kB
Tags Source
SHA-256 checksum
How to use checksums
0b550d521d9fcc57eabc630fde5db8eb4e8fd3bae15566e3974bf08f1e9e1fca
BLAKE2b-256 checksum
How to use checksums
c21a5b0791feade084923ceb778681010a26a4133339c622153c076b8f8c4044
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / yaratool-0.0.7-py3-none-any.whl

Download URL yaratool-0.0.7-py3-none-any.whl
Size 8.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0b3a193885821258ca39fdce175551d3089652781fb410178e9e47a7b220e4ed
BLAKE2b-256 checksum
How to use checksums
cd7cd1fa1d7bbe9849b1111897a5e3c09a74daa5fb4fc2dcca78026407347761
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / yaratool-0.0.7-py2-none-any.whl

Download URL yaratool-0.0.7-py2-none-any.whl
Size 8.5 kB
Tags Python 2
SHA-256 checksum
How to use checksums
f69856083ffe9655ec27d1992c7a3732e1ab836d55705093fbcf50fca8a81e3a
BLAKE2b-256 checksum
How to use checksums
d7bf4789f5e2b78f51a829a5fcb876986fe860f70da397ba6fa5b2651a2e39b1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.0.7 This release

3 release files

0.0.6

3 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page