{"repo":"CERT-Polska/mquery","free":true,"listed":false,"github":"https://github.com/CERT-Polska/mquery","clone":"git clone https://github.com/CERT-Polska/mquery.git","description":"YARA malware query accelerator (web frontend)","language":"Python","stars":440,"topics":["yara","malware","database","security-tools","security-automation"],"license":"AGPL-3.0","category":"databases-storage","readme_excerpt":"mquery: Blazingly fast Yara queries for malware analysts Ever had trouble searching for malware samples? Mquery is an analyst-friendly web GUI to look through your digital warehouse. It can be used to search through terabytes of malware in a blink of an eye: Under the hood we use our UrsaDB, to accelerate yara queries with ngrams. Demo Public instance will be created soon, stay tuned... Quickstart 1. Install and start The easiest way to do this is with docker compose : The web interface should be available at http://localhost . (For more installation options see the installation manual ). 2. Add the files Put some files in the SAMPLES DIR (by default ./samples in the repository, configurable with variable in the .env file). 3. Index your collection Launch ursacli in docker: Index the samples with n-grams of your choosing (this may take a while!) This will scan samples directory for all new files and index them. You can monitor the progress in the tasks window on the left: You have to repeat this process every time you want to add new files! After indexing is over, you will notice new datasets: This is a good and easy way to start, but if you have a big collection you are strongly encouraged to read indexing page in the manual. 4. Test it Now your files should be searchable - insert any Yara rule into the search window and click Query . Just for demonstration, I've indexed the source code of this application and tested this Yara rule: Learn more See the documentation to learn ","default_branch":null,"files":null,"tree":[],"storefront":"/r/CERT-Polska","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/CERT-Polska/mquery/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}