Yara
Jump to navigation
Jump to search
| Executable | Yara.exe
|
| Stage | 6 |
| Percent Complete | 48% |
| Message Queue | yara
|
Yara ETL uses the malware scanning tool called, well, YARA to scan files. When a rule hits, the file will be tagged with the name of the rule. If any tags were specified in the YARA rule, they will also be applied to the file.
File Types
Yara scan the following types of files:
- Type_Parsable_MIME
- Type_PE
- Type_32bit_Windows_Executable
- Type_64bit_Windows_Executable
- Type_ROM_Windows_Executable
- Type_Adobe_PDF
- Type_XP_Prefetch
- Type_Vista7_Prefetch
- Type_TrueType_Font
- Type_DOS_Executable
- Type_TrueType_Font_Collection
- Type_OpenType_Font
- Type_Windows_Registry
- Type_SAM_Registry
- Type_System_Registry
- Type_Boot_Registry
- Type_User_Registry
- Type_Software_Registry
- Type_Xbox_Executable
- Type_Xbox_360_Executable
- Type_Windows_Event_Log
- Type_ELF_Executable
- Type_Android_Executable_35
- Type_Android_Executable_36
- Type_Windows_Registry_Fragment
- Type_Windows_XML_Event_Log
- Type_Obfuscated_TrueType_Font
- Type_Apple_Mach_O_Executable
- Type_81_Prefetch
- Type_LUA
- Type_XBE_Executable
- Type_Compressed_Prefetch
- Type_10_Prefetch