Create and test your own Yara signatures



  • Our rating
Sending
User Rating 4.33 (3 votes)
YaraEditor is a software that will reduce to zéro the hassle of writing and testing signatures for the Yara engine. It can store your rules into a local database or operate on raw files with syntax highlighting.
Choose your plan
  •    Registration
    If machine registration is available
  •    Machines
    Number of machines allowed to register
  •    Custom plans
    If custom plans are available (Ex: company)
  •    Database model
    Edit/Save your rules from a database model (SQlite only)
  •    Editor
    Editor your rules, with syntax highlight
  •    Aliases
    Define aliases to replace long strings
  •    Limitation
    Software limitation
  •    Support
    Get support for your questions or feedback
  •    Automatic Updates
    Update the software with one click
  •    Themes
    Customize the software appearance using built-in themes

Personal

$49/year
  • 5
    You can register up to 5 machines with your license.
  • Special plans available for companies.
  • No limitation

Free

$0
  • 5 files
    5 files open at the same time

IconDownload YaraEditor (Desktop)
AuthorAdlice Software
Version2.3.0
Download997
Category,
File Size19.6 MB
LicenseFreemium
Operating SystemWindows XP, Vista, 7, 8, 8.1, 10. 32/64 bits
Tags   analysis     editor     malware     pe     reverse engineering     signatures     test     yara  
 
SCREENSHOTS
 
DESCRIPTION and REVIEW

Yara has become a pretty popular standard in the Anti-malware industry to write signatures for malware detections. Many Anti-malware vendors, sandboxes vendors, HIPS vendors, CERTs or IT administrators are using rules to either detect malware based on the file, or to analyze network packets and trigger an alert when something malicious occurs.

Yara is a signature syntax and scanning engine, it's available with a library or a bunch of scripts. We, at Adlice Software, are specialized in making Yara easy and convenient to use. We are offering a desktop application to write, organize and test your rules into a local database, or in text files.

YaraEditor is a FREE application built to make your life easier in writing your rules (editor with syntax highlight) and testing them (against files, strings, buffers). You can also leverage Yara's ability to compile the rules into binaries.

 

FEATURES

  • Syntax highlighting.
  • Drag N drop support.
  • Write yara signatures in a complete IDE.
  • Edit either from raw files, or in a database model (SQLite)
  • Compile rules and fix your errors.
  • Test your rules against strings (ANSI/Unicode).
  • Test your rules by scanning processes memory.
  • Test your rules by scanning files.
  • Test your rules by scanning folders.
  • Powerful rules search.
  • Write aliases to replace long (and repetitive) patterns at compilation.

 

DOCUMENTATION

Please refer to the dedicated documentation.
 

 
Download
FileAction
YaraEditor.exe (32 bits)Download 
YaraEditor.exe (64 bits)Download