#yara

yara

Rust bindings for VirusTotal/yara

13 releases (6 breaking)

new 0.8.0 Jul 22, 2021
0.6.1 May 6, 2021
0.4.4 Mar 23, 2021
0.4.2 Sep 8, 2020
0.1.0 May 30, 2018

#16 in FFI

Download history 80/week @ 2021-04-03 86/week @ 2021-04-10 93/week @ 2021-04-17 204/week @ 2021-04-24 90/week @ 2021-05-01 120/week @ 2021-05-08 106/week @ 2021-05-15 186/week @ 2021-05-22 36/week @ 2021-05-29 63/week @ 2021-06-05 36/week @ 2021-06-12 34/week @ 2021-06-19 26/week @ 2021-06-26 43/week @ 2021-07-03 255/week @ 2021-07-10 143/week @ 2021-07-17

421 downloads per month
Used in 3 crates

MIT/Apache

2.5MB
63K SLoC

C 44K SLoC // 0.1% comments Rust 12K SLoC // 0.0% comments Happy 3K SLoC Visual Studio Project 1.5K SLoC C++ 788 SLoC // 0.3% comments Automake 285 SLoC // 0.1% comments Batch 211 SLoC Visual Studio Solution 120 SLoC JavaScript 91 SLoC // 0.0% comments RPM Specfile 84 SLoC // 0.1% comments Python 34 SLoC // 0.8% comments Shell 3 SLoC

yara-rust

Build Status Crates.io Documentation

Bindings for the Yara library from VirusTotal.

More documentation can be found on the Yara's documentation.

Example

The implementation is inspired from yara-python.

const RULES: &str = r#"
    rule contains_rust {
      strings:
        $rust = "rust" nocase
      condition:
        $rust
    }
"#;

fn main() {
    let compiler = Compiler::new().unwrap();
    compiler.add_rules_str(RULES)
        .expect("Should have parsed rule");
    let rules = compiler.compile_rules()
        .expect("Should have compiled rules");
    let results = rules.scan_mem("I love Rust!".as_bytes(), 5)
        .expect("Should have scanned");
    assert!(results.iter().any(|r| r.identifier == "contains_rust"));
}

Features

  • Support from Yara v4.1.
  • Compile rules from strings or files.
  • Save and load compiled rules.
  • Scan byte arrays (&[u8]) or files.

Feature flags and Yara linking.

Look at the yara-sys crate documentation for a list of feature flags and how to link to your Yara crate.

TODO

  • Remove some unwrap on string conversions (currently this crate assume the rules, meta and namespace identifier are valid Rust's str).
  • Accept AsRef<Path> instead of &str on multiple functions.
  • Implement the scanner API.
  • Add process scanning.
  • Report the warnings to the user.

License

Licensed under either of

at your option.

Contributing

Please follow the conventional commit rules when committing to this repository.

If you add any new feature, add the corresponding unit/doc tests.

Dependencies