跳到主要内容
知仓学习社ZHICANG

YARA Rules Skill

YARA rule creation, testing, and deployment

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,2 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

YARA Rules Skill

Overview

This skill provides capabilities for YARA rule creation, testing, and deployment for malware detection and threat hunting.

Capabilities

  • Generate YARA rules from samples
  • Validate YARA rule syntax
  • Test rules against sample sets
  • Optimize rules for performance
  • Create rule metadata and documentation
  • Support YARA modules (PE, ELF, etc.)
  • Integrate with VirusTotal YARA
  • Generate Sigma rules for correlation

Target Processes

  • malware-analysis.js
  • threat-intelligence-research.js
  • security-tool-development.js

Dependencies

  • YARA CLI
  • yara-python library
  • VirusTotal API (optional)
  • Sample malware corpus (for testing)

Usage Context

This skill is essential for:

  • Malware detection rule development
  • Threat hunting operations
  • IOC-based detection
  • Malware family classification
  • Automated sample triage

Integration Notes

  • Rules can be tested against known good/bad samples
  • Performance metrics help optimize detection speed
  • Supports rule versioning and documentation
  • Can export to multiple detection platforms
  • Integrates with YARA-L for Chronicle

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。