The YARA Rules

YARA is a malware detection and classification tool. It allows you to create rules using strings, boolean expressions, wildcards, regular expressions, special operators, and other.

This section provides tools for creating and working with YARA rules. For more information about the YARA rules, check YARA documentation.

In this section you can:

search, filter, and sort rules;

monitor matches and navigate to the last match report;

add, edit, delete, and turn on/off the rules.

 

There areuser and system rules. In the rules list, they’re marked as user rule and system rule accordingly. User rules are the rules added within your account. System rules are added by the Dr.Web vxCube developers. You can disable any rule. Only user rules can be viewed, edited, or deleted.

 

yara rules

Figure 8. The list of YARA rules