EFF Releases YAYA, An Open Source Tool to Manage Multiple YARA Repositories

YARA is a “pattern matching swiss knife for malware researchers” designed to assist in identifying and classifying malware.

The Electronic Frontier Foundation has released YAYA, which is an open-source tool designed to allow malware researches to manage multiple YARA repositories.

Managing a ton of YARA rules in different repositories, plus your own sets of rules, can be a headache, so we decided to create a tool to help us manage our YARA rules and run scans. Today we are presenting this open source tool free to the public: YAYA, or Yet Another YARA Automation.

. . .

YAYA is a new open source tool to help researchers manage multiple YARA rule repositories. YAYA starts by importing a set of high-quality YARA rules and then lets researchers add their own rules, disable specific rulesets, and run scans of files. YAYA only runs on Linux systems for now. The program is geared towards new and experienced malware researchers, or those who want to get into malware research. No previous YARA knowledge is required to be able to run YAYA.

Leave a Reply