macOS
brew install yara-xlocal Homebrew formula metadata
安装
brew install yara-xlocal Homebrew formula metadata
nix profile install nixpkgs#yara-xnixpkgs package indexes · pkgs/by-name/ya/yara-x/package.nix · 来源: api.github.com
scoop install main/yara-xScoop official bucket manifest trees · bucket/yara-x.json · 来源: api.github.com
winget install --id VirusTotal.YARA-X -eWindows Package Manager source index · VirusTotal.YARA-X · 来源: cdn.winget.microsoft.com
概览
Tool to do pattern matching for malware research
历史
YARA-X is VirusTotal's Rust rewrite and intended successor to YARA, the rule-based pattern-matching tool used heavily in malware research. It keeps YARA's rule-language lineage while aiming for better safety, performance, user-friendliness, and modern library APIs.
The yara-x repository was created on 2022-10-14. Upstream describes YARA-X as a re-incarnation of YARA whose ultimate goal is to replace YARA as the default pattern-matching tool for malware researchers. The rewrite also moves the implementation from C into Rust while exposing C/C++, Python, Go, and Rust APIs.
Victor M. Alvarez's 2024 post 'YARA is dead, long live YARA-X' explained the transition without actually abandoning YARA: YARA would continue to receive bug fixes and minor features, while major new modules and enhancements would focus on YARA-X. VirusTotal had already been running the new engine alongside YARA and comparing results at large scale.
YARA-X reached its public stability milestone with v1.0.0 on 2025-06-04. The accompanying YARA-X blog post says the release ended the beta phase and that the original YARA project entered maintenance mode, with future innovation happening in YARA-X.
The most important adoption signal came from VirusTotal itself. In December 2024, VirusTotal announced that YARA-X had replaced YARA as the engine powering Livehunt and Retrohunt, two production services where rule compatibility and scale matter more than novelty.
Adoption is intentionally migration-shaped rather than greenfield. The docs emphasize high rule compatibility, explain the differences with YARA, and encourage existing YARA users to explore YARA-X without requiring a rushed cutover.
The packaged CLI is `yr`. Users write familiar YARA-style rules with patterns and conditions, then scan files or integrate the engine through language bindings. YARA-X also adds modern tooling around the rule lifecycle, including formatting, checking, warnings, a configuration file for some commands, and a language server.
Practical usage today is split between command-line malware hunting, CI-style rule validation, and embedding YARA-compatible matching in security products or research pipelines that benefit from Rust's safety and newer APIs.
YARA-X is package-nerd significant because it is a rare live succession story for a security standard tool: not a fork competing with the old package, but the same steward moving a widely packaged C utility toward a Rust implementation while preserving rule compatibility.
It also changes the shape of the package from a classic CLI/library pair into a broader toolchain: formatter, checker, language server, multi-language APIs, and a migration target for years of existing YARA rules.
安全态势
narrow executable package without higher-risk signals.
绿色 风险 · 低 置信度 · appliance
在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。
可执行文件
| 命令 | 类型 | 暴露范围 | 备注 |
|---|---|---|---|
yr | 可执行文件 | 已索引可执行文件 | 从本地可执行文件索引发现。 |
新鲜度
这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。
安装元数据
| 软件包键 | brew:yara-x |
|---|---|
| 版本 | 1.19.0 |
| 软件包管理器 | Homebrew |
| 主页 | https://virustotal.github.io/yara-x/ |
| 仓库 | https://github.com/VirusTotal/yara-x |
| 最后更新 | 2026-06-24T17:31:08Z |
| Pulse | updated |
| Bottle | 未记录 |
| 服务 | 未声明 |
源数据库匹配
匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。
yara-x
nix profile install nixpkgs#yara-xmain/yara-x
scoop install main/yara-xVirusTotal.YARA-X
winget install --id VirusTotal.YARA-X -e来源线索
此页面由 av-web 从 scripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。
View the package source record on GitHub.