Yara python module – part 001

YARA is a multi-platform program running on Windows, Linux and Mac OS X.
More about yara python module can be see it here
YARA used this keywords with rules under files.

The Yara documentation can be found in this link.
The yara python module use version 1.7.7 and this will need to use when make rules.
Instalation with pip :

Let’s see this in action.
First you need to make your user under your_user account.
I make one folder named yara to keep the my rules, see:

and I test this file named doc_data.txt, from here:

The file has this text :

and the rule file detectstring has this rule:

You can use python shell with this source code:

The above rule is telling YARA that the file containing the string must be reported.
The print will show the rule compiled and the result.
[caption id="attachment_1448" align="alignleft" width="594"]yara python yara python[/caption]