yara
A malware identification and classification tool
YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns.
homepage ↗ github: VirusTotal/yara
Available in
| Overlay | Newest | Ebuilds | Last activity | |
|---|---|---|---|---|
| gentoo gitweb ↗ | 4.5.5 | 3 | 15 h | details › |
Versions & arches
| Version | Overlay | amd64 | arm64 | x86 | ppc64 | Committed | |
|---|---|---|---|---|---|---|---|
| 9999 LIVE | gentoo | follows upstream — no keywords | — | view · download · history ↗ | |||
| 4.5.5 | gentoo | amd64 stable | arm64 testing | x86 stable | ppc64 testing | — | view · download · history ↗ |
| 4.5.4 | gentoo | amd64 stable | arm64 testing | x86 stable | ppc64 testing | — | view · download · history ↗ |
Use flags of 4.5.5
- +dex Enable dex module
- +dotnet Enable dotnet module
- +cuckoo Enable cockoo module
- +macho Enable macho module
- +magic Enable magic module
- profiling Enable rules profiling
- python Pulls in python binding via dev-python/yara-python
- test Enable dependencies and/or preparations necessary to run tests (usually controlled by FEATURES=test but can be toggled independently)