YARA Rules
YARA rules describe patterns in files and memory used to detect and classify malware.
YARA is a tool and rule format for identifying and classifying files based on patterns. It is primarily used to identify malware and its variants.
How it works
A YARA rule describes a file's typical characteristics, like specific text strings or byte patterns. It can also describe properties of the file's structure. A condition defines which combination of these features constitutes a match. YARA then scans files, memory dumps, or email attachments for these patterns. Many security products and sandboxes offer direct support for YARA rules.
For example, during an incident, the SOC finds an unknown executable file. Analysis reveals a suspicious string and a specific encryption routine. A YARA rule is then created from these findings. A scan across all servers finds two more copies in another directory.
What to look out for
- Rules that are too general may also match legitimate software.
- Rules that are too specific can miss slightly modified variants.
- Test new rules against a collection of known benign files.
- Document the origin and purpose of every rule.
- Remember that YARA inspects files, not system behaviour.
How it differs from Sigma
Sigma describes patterns in logs, which represent events. YARA describes patterns in files and memory. The two are complementary. Sigma detects suspicious sequences of events, while YARA classifies discovered files.
Use in the SOC
YARA is mainly used in investigations and for threat hunting. After an incident, it helps to find other affected systems. Many CTI reports also contain YARA rules that can be used directly.
Typical mistakes
Publicly available rules are often used without prior testing. Some may match common libraries, creating many false positives. Another mistake is lacking a process to evaluate matches quickly.
How we implement it
In the SOC, we primarily detect malware using EDR and behavioural rules.