{"repo":"Neo23x0/yarGen","free":true,"listed":false,"github":"https://github.com/Neo23x0/yarGen","clone":"git clone https://github.com/Neo23x0/yarGen.git","description":"yarGen is a generator for YARA rules","language":"Python","stars":1809,"topics":["python","yara","malware","malware-research","malware-analysis","malwareanalysis"],"license":null,"category":"security-tools","readme_excerpt":"I created a new YARA rule generator named yarGen-Go (Golang). yarGen / / / // / / / ( / - ) \\ \\ , /\\ , / / \\ /\\ / // / / / Yara Rule Generator Florian Roth, July 2020, Version 0.23.2 Note: Rules have to be post-processed See this post for details: https://medium.com/@cyb3rops/121d29322282 What does yarGen do? yarGen is a generator for YARA rules The main principle is the creation of yara rules from strings found in malware files while removing all strings that also appear in goodware files. Therefore yarGen includes a big goodware strings and opcode database as ZIP archives that have to be extracted before the first use. In version 0.24.0, yarGen introduces an output option ( --ai ). This feature generates a YARA rule with an expanded set of strings and includes instructions tailored for an AI. I suggest employing ChatGPT Plus with model 4 to refine these rules. Activating the --ai flag appends the instruction text to the yargen rules.yar output file, which can subsequently be fed into your AI for processing. With version 0.23.0 yarGen has been ported to Python3. If you'd like to use a version using Python 2, try a previous release. (Note that the download location for the pre-built databases has changed, since the database format has been changed from the outdated pickle to json . The old databases are still available but in an old location on our web server only used in the old yarGen version <0.23) Since version 0.12.0 yarGen does not completely remove the goodware strings","default_branch":null,"files":null,"tree":[],"storefront":"/r/Neo23x0","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Neo23x0/yarGen/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}