mirror of
https://github.com/stellarbear/YaraSharp
synced 2026-06-08 17:36:09 +00:00
7b36024001879e6573be954a02669dd0a5b37073
YaraSharp
C# wrapper around the Yara pattern matching library.
Use signatures form Loki or Yara.
Usage
// All API calls happens here
YaraSharp.CYaraSharp YSInstance = new CYaraSharp();
// Declare external variables (could be null)
Dictionary<string, object> Externals = new Dictionary<string, object>()
{
{ "filename", string.Empty },
{ "filepath", string.Empty },
{ "extension", string.Empty }
};
// Errors occured during rule compilation: ignored_file : List<reasons>
Dictionary<string, List<string>> Errors = new Dictionary<string, List<string>>();
// Context is where yara is initialized
// From yr_initialize() to yr_finalize()
using (YaraSharp.CContext YSContext = new YaraSharp.CContext())
{
// Compiling rules
using (YaraSharp.CRules YSRules = YSInstance.CompileFromFiles(RuleFilenames, Externals, out Errors))
{
// Some file to test yara rules
// Here comes long filenames
string Filename = "\\?\<some_file>";
// Get matches
List<YaraSharp.CMatches> Matches = YSInstance.ScanFile(Filename, YSRules,
new Dictionary<string, object>()
{
{ "filename", Alphaleonis.Win32.Filesystem.Path.GetFileName(Filename) },
{ "filepath", Alphaleonis.Win32.Filesystem.Path.GetFullPath(Filename) },
{ "extension", Alphaleonis.Win32.Filesystem.Path.GetExtension(Filename) }
},
0);
// Iterate over matches
foreach (YaraSharp.CMatches Match in Matches)
{
//...
}
}
// Log errors
}
For async scanning use must call destroy methods:
YaraSharp.CYaraSharp YSInstance = new CYaraSharp();
YaraSharp.CContext YSContext = new YaraSharp.CContext();
YaraSharp.CRules YSRules = YSInstance.CompileFromFiles(RuleFilenames, null, out Errors);
// Async here
YSRules.Destroy();
YSContext.Destroy();
Reference
Libyara C API documentation for a general overview on how to use libyara.
Features and limitations
- Metadata supported
- Externals supported
- Async scanning supported
- It seems (through debug sessions) that modules are supported, but i haven't had cases that certanly used them. So this question is opened
Note
Soultion contains 2 projects:
- yara-master - where you can update yara sources for a new version
- YaraSharp - where you can modify sources in order to add / repair wrapper features
Other
Build in vs 2017
Compiled with yara 3.7.0
You can use or modify the sources however you want
Special thanks to kallanreed
Languages
C
89.6%
Yacc
3.8%
C++
2.5%
Lex
1.9%
M4
0.5%
Other
1.6%