pkg.soopen package index

brew / 順位 3404

yara-x を Homebrew, Nix, scoop, winget でインストール

yara-x のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install yara-x

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#yara-x

nixpkgs package indexes · pkgs/by-name/ya/yara-x/package.nix · ソース: api.github.com

Windows

Scoop確認済み · 92%
scoop install main/yara-x

Scoop official bucket manifest trees · bucket/yara-x.json · ソース: api.github.com

Windows Package Manager確認済み · 92%
winget install --id VirusTotal.YARA-X -e

Windows Package Manager source index · VirusTotal.YARA-X · ソース: cdn.winget.microsoft.com

概要

パッケージ概要

Tool to do pattern matching for malware research

コマンドとエイリアス

  • yr

履歴

プロジェクトの歴史と使われ方

YARA-X is VirusTotal's Rust rewrite and intended successor to YARA, the rule-based pattern-matching tool used heavily in malware research. It keeps YARA's rule-language lineage while aiming for better safety, performance, user-friendliness, and modern library APIs.

プロジェクトの歴史

The yara-x repository was created on 2022-10-14. Upstream describes YARA-X as a re-incarnation of YARA whose ultimate goal is to replace YARA as the default pattern-matching tool for malware researchers. The rewrite also moves the implementation from C into Rust while exposing C/C++, Python, Go, and Rust APIs.

Victor M. Alvarez's 2024 post 'YARA is dead, long live YARA-X' explained the transition without actually abandoning YARA: YARA would continue to receive bug fixes and minor features, while major new modules and enhancements would focus on YARA-X. VirusTotal had already been running the new engine alongside YARA and comparing results at large scale.

YARA-X reached its public stability milestone with v1.0.0 on 2025-06-04. The accompanying YARA-X blog post says the release ended the beta phase and that the original YARA project entered maintenance mode, with future innovation happening in YARA-X.

採用の歴史

The most important adoption signal came from VirusTotal itself. In December 2024, VirusTotal announced that YARA-X had replaced YARA as the engine powering Livehunt and Retrohunt, two production services where rule compatibility and scale matter more than novelty.

Adoption is intentionally migration-shaped rather than greenfield. The docs emphasize high rule compatibility, explain the differences with YARA, and encourage existing YARA users to explore YARA-X without requiring a rushed cutover.

使われ方

The packaged CLI is `yr`. Users write familiar YARA-style rules with patterns and conditions, then scan files or integrate the engine through language bindings. YARA-X also adds modern tooling around the rule lifecycle, including formatting, checking, warnings, a configuration file for some commands, and a language server.

Practical usage today is split between command-line malware hunting, CI-style rule validation, and embedding YARA-compatible matching in security products or research pipelines that benefit from Rust's safety and newer APIs.

パッケージ好きにとっての重要性

YARA-X is package-nerd significant because it is a rare live succession story for a security standard tool: not a fork competing with the old package, but the same steward moving a widely packaged C utility toward a Rust implementation while preserving rule compatibility.

It also changes the shape of the package from a classic CLI/library pair into a broader toolchain: formatter, checker, language server, multi-language APIs, and a migration target for years of existing YARA rules.

タイムライン

  • 2022-10-14: VirusTotal/yara-x repository is created.
  • 2024-02-21: VirusTotal publishes 'YARA is dead, long live YARA-X', describing YARA-X as the future development focus.
  • 2024-12-04: VirusTotal announces YARA-X powers Livehunt and Retrohunt.
  • 2025-06-04: YARA-X 1.0.0 is released as the first stable release.
  • 2026-06-24: YARA-X v1.19.0 is published in GitHub releases.

Related projects

  • YARA is the original C implementation and rule-language predecessor now in maintenance mode.
  • yara-python is the long-standing Python binding for classic YARA; YARA-X provides its own Python API.
  • VirusTotal Livehunt and Retrohunt are production services that moved to YARA-X.

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
yr実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版1.19.0
マネージャ更新日2026-06-24
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:yara-x
バージョン1.19.0
パッケージマネージャHomebrew
ホームページhttps://virustotal.github.io/yara-x/
リポジトリhttps://github.com/VirusTotal/yara-x
最終更新2026-06-24T17:31:08Z
Pulseupdated
Bottle未記録
サービス宣言なし

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

yara-x

nix profile install nixpkgs#yara-x
  • normalized package name match
  • 一致条件: Yara X
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ya/yara-x/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop95%

main/yara-x

scoop install main/yara-x
  • normalized package name match
  • 一致条件: Yara X
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/yara-x.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

VirusTotal.YARA-X

winget install --id VirusTotal.YARA-X -e
  • normalized package name match
  • 一致条件: Yara X
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: VirusTotal.YARA-X from https://cdn.winget.microsoft.com/cache/source.msix

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • pkg.so package database
  • pkgdb category and tag curation