Running YARA from the command-line

In order to invoke YARA you’ll need two things: a file with the rules you want to use (either in source code or compiled form) and the target to be scanned. The target can be a file, a folder, or a process.

yara [OPTIONS] RULES_FILE TARGET

Rule files can be passed directly in source code form, or can be previously compiled with the yarac tool. You may prefer to use your rules in compiled form if you are going to invoke YARA multiple times with the same rules. This way you’ll save time, because for YARA it is faster to load compiled rules than compiling the same rules over and over again.

The rules will be applied to the target specified as the last argument to YARA, if it’s a path to a directory all the files contained in it will be scanned. By default YARA does not attempt to scan directories recursively, but you can use the -r option for that.

Available options are:

Here you have some examples:

  • Apply rule in /foo/bar/rules to all files in the current directory. Subdirectories are not scanned:

    yara /foo/bar/rules  .
  • Apply rules in /foo/bar/rules to bazfile. Only reports rules tagged as Packer or Compiler:

    yara -t Packer -t Compiler /foo/bar/rules bazfile
  • Scan all files in the /foo directory and its subdirectories:

    yara -r /foo
    
  • Defines three external variables mybool, myint and mystring:

    yara -d mybool=true -d myint=5 -d mystring="my string" /foo/bar/rules bazfile
  • Apply rules in /foo/bar/rules to bazfile while passing the content of cuckoo_json_report to the cuckoo module:

    yara -x cuckoo=cuckoo_json_report /foo/bar/rules bazfile

Previous topic

Writing your own modules

Next topic

Using YARA from Python

This Page