Official agent skill

YARA-X Rule Authoring

by trailofbits in trailofbits/skills

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install YARA-X Rule Authoring

skills CLI
$ npx skills add trailofbits/skills --skill yara-rule-authoring -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills yara-rule-authoring --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/yara-authoring/skills/yara-rule-authoring .claude/skills/yara-rule-authoring && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
yara-rule-authoring
GitHub stars
7.4k
Token cost
~5.9k tokens
SKILL.md length
2,484 words
Files
22 (incl. scripts, references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA.

  • Works in 5 steps: Strings must generate good atoms — YARA… → Target specific families, not categories… → Test against goodware before deployment… → …
  • Writing a new YARA-X rule for a malware family
  • SKILL.md covers Core Principles, When to Use, When NOT to Use and Platform Considerations, plus 15 more sections
  • Runs Python scripts from its folder; calls uv, brew and cargo

What it does

The skill targets YARA-X, the Rust-based successor to legacy YARA, installed with brew or cargo and run through the yr CLI. Its principles: pick strings that yield good four-byte atoms, aim rules at specific malware families rather than broad categories, test against a goodware corpus before deployment, order cheap checks first (file size, magic bytes, strings, then modules), and treat metadata as documentation of what a rule catches and where the sample came from.

It lists when to use it, such as writing rules, optimizing slow rulesets, turning IOCs into signatures, debugging false positives, migrating legacy rules and analyzing Chrome extensions or Android apps with the crx and dex modules, and when not to, such as disassembly, sandbox analysis, network detection or memory forensics. The folder carries reference notes on strings, performance, style, testing and the two modules, five example rules, and an atom analyzer script.

When your agent uses it

  • Writing a new YARA-X rule for a malware family
  • Reviewing or speeding up an existing ruleset
  • Reducing false positives before putting rules into production
  • Converting legacy YARA rules to YARA-X

Example prompts

  • “Write a YARA-X rule for this sample's configuration routine and check that its strings make good atoms.”
  • “Review rules/remcos.yar for performance problems and false-positive risk.”
  • “Migrate our legacy YARA ruleset to YARA-X and flag anything that needs manual changes.”

Requirements

  • YARA-X, installed with brew install yara-x or cargo install yara-x

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Strings must generate good atoms — YARA extracts 4-byte subsequences for fast matching. Strings with repeated bytes, common sequences, or…
  2. Target specific families, not categories — "Detects ransomware" catches everything and nothing. "Detects LockBit 3.0 configuration…
  3. Test against goodware before deployment — A rule that fires on Windows system files is useless. Validate against VirusTotal's goodware…
  4. Short-circuit with cheap checks first — filesize (instant), then magic bytes (nearly instant), then strings (cheap), then modules…
  5. Metadata is documentation — Future you (and your team) need to know what this catches, why, and where the sample came from.

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • uv
    • brew
    • cargo
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • virustotal.github.io
    • objective-see.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

YARA-X Rule Authoring loads about 5.9k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 2,484 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~5.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~21k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 2,484 words, ~5,921 tokens.

Download SKILL.mdSave it as .claude/skills/yara-rule-authoring/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.
name
yara-rule-authoring
description
Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction. Triggers on: YARA, YARA-X, malware detection, threat hunting, IOC, signature, crx module, dex module.

YARA-X Rule Authoring

Write detection rules that catch malware without drowning in false positives.

This skill targets YARA-X, the Rust-based successor to legacy YARA — 5-10x faster regex, better errors, built-in formatter, stricter validation, new modules (crx, dex), 99% rule compatibility. It powers VirusTotal's production systems. Install with brew install yara-x or cargo install yara-x; the CLI is yr. See Migrating from Legacy YARA for existing rules.

Core Principles

  1. Strings must generate good atoms — YARA extracts 4-byte subsequences for fast matching. Strings with repeated bytes, common sequences, or under 4 bytes force slow bytecode verification on too many files.

  2. Target specific families, not categories — "Detects ransomware" catches everything and nothing. "Detects LockBit 3.0 configuration extraction routine" catches what you want.

  3. Test against goodware before deployment — A rule that fires on Windows system files is useless. Validate against VirusTotal's goodware corpus or your own clean file set.

  4. Short-circuit with cheap checks first — filesize (instant), then magic bytes (nearly instant), then strings (cheap), then modules (expensive).

  5. Metadata is documentation — Future you (and your team) need to know what this catches, why, and where the sample came from.

When to Use

  • Writing new YARA-X rules for malware detection
  • Reviewing existing rules for quality or performance issues
  • Optimizing slow-running rulesets
  • Converting IOCs or threat intel into detection signatures
  • Debugging false positive issues
  • Preparing rules for production deployment
  • Migrating legacy YARA rules to YARA-X
  • Analyzing Chrome extensions (crx module) or Android apps (dex module)

When NOT to Use

  • Static analysis requiring disassembly → use Ghidra/IDA skills
  • Dynamic malware analysis → use sandbox analysis skills
  • Network-based detection → use Suricata/Snort skills
  • Memory forensics with Volatility → use memory forensics skills
  • Simple hash-based detection → just use hash lists

Platform Considerations

YARA works on any file type. Adapt patterns to your target:

PlatformMagic BytesBad StringsGood Strings
Windows PEuint16(0) == 0x5A4DAPI names, Windows pathsMutex names, PDB paths
macOS Mach-Ouint32(0) == 0xFEEDFACE (32-bit), 0xFEEDFACF (64-bit), uint32be(0) == 0xCAFEBABE (universal)Common Obj-C methodsKeylogger strings, persistence paths
JavaScript/Node(none needed)require, fetch, axiosObfuscator signatures, eval+decode chains
npm/pip packages(none needed)postinstall, dependenciesSuspicious package names, exfil URLs
Office docsuint32(0) == 0x04034B50VBA keywordsMacro auto-exec, encoded payloads
VS Code extensions(none needed)vscode.workspaceUncommon activationEvents, hidden file access
Chrome extensionsUse crx moduleCommon Chrome APIsPermission abuse, manifest anomalies
Android appsUse dex moduleStandard DEX structureObfuscated classes, suspicious permissions

uintNN() reads little-endian. Write the constant as the bytes reversed, or use uintNNbe() and write them in file order. A ZIP/OOXML file starts with bytes 50 4B 03 04, so it is uint32(0) == 0x04034B50 — uint32(0) == 0x504B0304 compiles cleanly and never matches anything. The same trap catches Mach-O universal binaries: on disk they are CA FE BA BE, so uint32(0) == 0xCAFEBABE is a dead branch; write uint32be(0) == 0xCAFEBABE or uint32(0) == 0xBEBAFECA. Verify with yr scan against one known-good sample before trusting any magic-byte check.

macOS Malware Detection

No dedicated Mach-O module exists yet — use magic bytes plus string patterns. Good indicators:

  • Keylogger artifacts: CGEventTapCreate, kCGEventKeyDown
  • SSH tunnel strings: ssh -D, tunnel, socks
  • Persistence paths: ~/Library/LaunchAgents, /Library/LaunchDaemons
  • Credential theft: security find-generic-password, keychain
yara
// Pattern from Airbnb BinaryAlert
rule SUSP_Mac_ProtonRAT
{
    strings:
        $lib1 = "SRWebSocket" ascii          // Library indicators
        $lib2 = "SocketRocket" ascii
        $behav1 = "SSH tunnel not launched" ascii   // Behavioral indicators
        $behav2 = "Keylogger" ascii
    condition:
        (uint32(0) == 0xFEEDFACF or uint32be(0) == 0xCAFEBABE) and
        any of ($lib*) and any of ($behav*)
}
JavaScript Detection
TargetApproach
npm packagepackage.json patterns, postinstall/preinstall hooks, exfil combination: fetch + env access + credential paths
Chrome extensioncrx module
Other extensionManifest patterns, background script behaviors
Standalone JSObfuscation markers (eval+atob, fromCharCode chains), unique function/variable names, packed payloads
Minified/webpack bundleUnique strings that survive bundling (URLs, magic values); avoid function names — they get mangled

Good JS strings: Ethereum function selectors — { a9 05 9c bb } (transfer(address,uint256)), { 70 a0 82 31 } (balanceOf(address)); zero-width characters for steganography — { E2 80 8B E2 80 8C }; obfuscator signatures — _0x, var _0x; specific C2 domains and webhook URLs.

Bad JS strings: require, fetch, axios (too common); Buffer, crypto (legitimate uses everywhere); process.env alone (need specific env var names).

String Selection

Value ranking: mutex names are gold, C2 paths silver, error messages bronze. Stack strings are almost always unique. If you need more than 6 strings, you're over-fitting.

Reject a candidate string when any of these holds:

TestWhy it failsDo instead
Under 4 bytesNo atomFind a longer string
Repeated bytes (0000, 9090)Weak atomAdd surrounding context
API name (VirtualAlloc, CreateRemoteThread)Every packer and installer calls itHex pattern of the call site plus a unique marker
Appears in Windows system filesGuaranteed FPsFind something family-specific
Common path (C:\Windows\, cmd.exe)UbiquitousFind malware-specific paths
Appears in other malware familiesNot identifying this familyCombine with a family-specific marker

Everything left — unique to this family — is what the rule should rest on.

Choosing a String Type
NeedUse
Exact ASCII/Unicode text$s = "MutexName" ascii wide
Specific byte sequence$h = { 4D 5A 90 00 }
Byte sequence with variationHex wildcards: { 4D 5A ?? ?? 50 45 }
Pattern with structure (URLs, paths)Bounded regex: /https:\/\/[a-z]{5,20}\.onion/
Unknown encoding (XOR, base64)Modifier: $s = "config" xor(0x00-0xFF)

Modifier discipline: never use nocase or wide speculatively — only with confirmed evidence that case or encoding varies across samples. nocase doubles atom generation; wide doubles string matching. "If you don't have a clear reason for using those modifiers, don't do it" — Kaspersky Applied YARA.

Condition Design

Order for short-circuit: filesize <, magic bytes, strings, modules. If the condition runs past 5 lines, split into multiple rules.

all of vs any of
SituationUse
Strings are individually unique to the malwareany of them — each alone is suspicious
Strings are common but the combination is suspiciousall of them — require the full pattern
Strings have different confidence levelsGroup: all of ($core_*) and any of ($variant_*)
Seeing false positivesTighten: any → all, add more required strings

Lesson from production: rules using any of ($network_*) where the strings included fetch, axios, and http matched virtually all web applications. Switching to require a credential path AND a network call AND an exfil destination eliminated the FPs.

Grouping by Confidence

Different indicator types carry different weight — a C2 domain might be definitive while library imports need corroboration. Grouping by prefix lets you express graduated requirements:

yara
strings:
    $a1 = "SRWebSocket" ascii            // Category A: library indicators
    $a2 = "SocketRocket" ascii
    $b1 = "SSH tunnel" ascii             // Category B: behavioral
    $b2 = "keylogger" ascii nocase
    $c1 = /https:\/\/[a-z0-9]{8,16}\.onion/   // Category C: C2

condition:
    filesize < 10MB and
    any of ($a*) and any of ($b*)        // Evidence from BOTH categories
Modules vs Byte Checks
NeedUse
imphash, rich header, authenticodePE module — too complex to replicate
Magic bytes or simple offsetsuint16/uint32 — faster, no module overhead
Section names/sizesPE module, but put the magic-byte filter FIRST
Chrome extension permissionscrx module — string parsing is fragile
LNK target pathslnk module — the format is complex

"Avoid the magic module — use explicit hex checks instead" — Neo23x0. Generalize it: if uint32() can do the job, don't load a module.

Performance
  • Regex must be anchored to a 4+ byte literal. Without one it evaluates at every file offset — catastrophic. Write /mshta\.exe http:\/\/.../, not /http:\/\/.../. If you can't anchor, use a hex pattern with wildcards.
  • Bound every regex quantifier — .{0,30}, never .*. Unbounded regex is both a performance disaster and a memory explosion.
  • Bound loops with filesize — filesize < 100KB and for all i in (1..#a) : .... Unbounded #a can reach thousands in large files.
  • Prefer hex over regex where the bytes are fixed.

Before Writing: Is the Sample Packed?

SignalWhat to do
Entropy > 7.0Likely packed — find the unpacked layer first
Few or no readable stringsLikely packed — use entropy, PE structure, or packer signatures
UPX/MPRESS/custom packer detectedTarget the unpacked payload OR detect the packer itself
Readable strings availableProceed with string-based detection

Don't write rules against packed layers. The packing changes; the payload doesn't.

When Strings Fail, Pivot to Structure

If extraction returns only API names and generic paths:

Available signalUse
High entropy sectionsmath.entropy() on specific sections
Unusual import patternpe.imphash() for import-hash clustering
PE structure anomaliesSection names, sizes, characteristics
Metadata presentVersion info, timestamps, resources
Nothing uniqueThis sample may not be detectable with YARA alone

"One can try to use other file properties, such as metadata, entropy, import hashes or other data which stays constant." — Kaspersky Applied YARA Training

Debugging False Positives

  1. Which string matched? — yr scan -s rule.yar false_positive.exe
  2. In a legitimate library? — add a not $fp_vendor_string exclusion
  3. A common development pattern? — replace the string with something more specific
  4. Multiple generic strings matching together? — tighten to require all, plus a unique marker
  5. Malware using a common technique? — target its specific implementation details, not the technique
When to Abandon the Approach
  • Extraction returns only API names and paths → pivot to structure
  • Can't find 3 unique strings → probably packed; target the unpacked version or detect the packer
  • Rule matches goodware → 1-2 matches: investigate and tighten; 3-5: find different indicators; 6+: start over
  • Performance is terrible after optimization → architecture problem; split into focused rules or add strict pre-filters
  • The description is hard to write → the rule is too vague. If you can't explain what it catches, it catches too much
Show full SKILL.md (1,047 more words)Show less

Rationalizations to Reject

When you catch yourself thinking these, stop and reconsider.

RationalizationExpert Response
"This generic string is unique enough" / "This hex pattern is unique"Unique in one sample ≠ unique across the ecosystem. Test against goodware; your intuition is wrong.
"yarGen gave me these strings"yarGen suggests, you validate. Check each one manually — expect to discard 80%.
"It works on my 10 samples"10 samples ≠ production. Use a goodware corpus.
"One rule to catch all variants"Causes FP floods. Target specific families.
"I'll make it more specific if we get FPs" / "I'll add more conditions later"Write tight rules upfront. A weak rule deployed is damage done, and FPs burn trust.
"This is just for hunting"Hunting rules become detection rules. Same quality bar.
"The API name makes it malicious"Legitimate software uses the same APIs. Need behavioral context.
"any of them is fine for these common strings"Common strings + any = FP flood. Use any of only for individually unique strings.
"This regex is specific enough"/fetch.*token/ matches all auth code. Add an exfil destination requirement.
"I'll use .* for flexibility"Unbounded regex = performance disaster plus memory explosion. Use .{0,30}.
"The JavaScript looks clean"Attackers poison legitimate code with injects. Check for eval+decode chains.
"Performance doesn't matter"One slow rule slows the entire ruleset. Optimize atoms.
"I'll use --relaxed-re-syntax everywhere"Masks real bugs. Fix the regex instead of hiding the problem.
"PEiD rules still work"Obsolete. 32-bit packers aren't relevant.

Toolkit

ToolPurpose
yr CLIyr check (validate), yr fmt (format), yr scan -s (scan, show strings), yr dump -m pe (inspect structure)
yarGenExtract candidate strings: yarGen.py -m samples/ --excludegood
FLOSSExtract obfuscated/stack strings: floss sample.exe — when yarGen comes up empty
signature-baseStudy quality examples
YARA-CIGoodware corpus testing before deployment

Master these five. Don't get distracted by tool catalogs.

Development cycle:

bash
yr check rule.yar                                   # syntax, with precise line numbers
yr fmt -w rule.yar                                  # standardize formatting
yr dump -m pe sample.exe --output-format yaml       # inspect structure, no dummy rule needed
time yr scan -s rule.yar corpus/                    # scan with timing

Reach for yr dump when investigating which module fields are available, debugging why a module condition isn't matching, or exploring a new module (crx, lnk, dotnet) before writing against it. YARA-X error messages carry precise source locations — if yr check says line 15, the problem is on line 15.

Version-gated features: private $helper = "pattern" matches but stays out of output (v1.3.0+); // suppress: slow_pattern silences a specific warning inline (v1.4.0+); filesize < 10_000_000 numeric underscores (v1.5.0+). $_unused also suppresses unused-string warnings.

Chrome Extension Analysis (crx module)

Requires YARA-X v1.5.0+, or v1.11.0+ for permhash().

Key APIs: crx.is_crx, crx.permissions, crx.permhash() Red flags: nativeMessaging + downloads, debugger permission, content scripts on <all_urls>

yara
import "crx"

rule SUSP_CRX_HighRiskPerms {
    condition:
        crx.is_crx and
        for any perm in crx.permissions : (perm == "debugger")
}

See crx-module.md for the full API, permission risk assessment, and example rules.

Android DEX Analysis (dex module)

Requires YARA-X v1.11.0+. Not compatible with legacy YARA's dex module — the API is completely different.

Key APIs: dex.is_dex, dex.contains_class(), dex.contains_method(), dex.contains_string() Red flags: single-letter class names (obfuscation), DexClassLoader reflection, encrypted assets

yara
import "dex"

rule SUSP_DEX_DynamicLoading {
    condition:
        dex.is_dex and
        dex.contains_class("Ldalvik/system/DexClassLoader;")
}

See dex-module.md for the full API, obfuscation detection, and example rules.

Migrating from Legacy YARA

99% rule compatibility, but stricter validation:

bash
yr check --relaxed-re-syntax rules/   # identify issues
# fix each one, then verify without relaxed mode:
yr check rules/
IssueLegacyYARA-X Fix
Literal { in regex/{//\{/
Invalid escapes\R silently literal\\R or R
Base64 stringsAny length3+ chars required
Negative indexing@a[-1]@a[#a - 1]
Duplicate modifiersAllowedRemove duplicates

--relaxed-re-syntax is a diagnostic, not a destination. Fix the regex.

Naming and Metadata

{CATEGORY}_{PLATFORM}_{FAMILY}_{VARIANT}_{DATE}      e.g. MAL_Win_Emotet_Loader_Jan25

Categories: MAL_ (malware), HKTL_ (hacking tool), WEBSHELL_, EXPL_, SUSP_ (suspicious), GEN_ (generic). Platforms: Win_, Lnx_, Mac_, Android_, CRX_.

Every rule needs description (starting with "Detects"), author, reference, and date:

yara
meta:
    description = "Detects Example malware via unique mutex and C2 path"
    author = "Your Name <email@example.com>"
    reference = "https://example.com/analysis"
    date = "2025-01-29"

See style-guide.md for full conventions.

Workflow

  1. Gather samples — multiple; single-sample rules are brittle
  2. Extract candidates — yarGen -m samples/ --excludegood
  3. Validate quality — apply the string selection tests; expect to discard 80% of yarGen output
  4. Write the rule — proper metadata, cheap checks first
  5. Lint and test — yr check, yr fmt, the linter script
  6. Goodware validation — VirusTotal corpus or local clean files
  7. Deploy — full metadata, then monitor for FPs

Quality signals along the way: a rule matching under 50% of known variants is too narrow; one matching goodware is too broad.

Reviewing a rule someone else wrote — run both scripts before reading the rule by eye, and quote the codes they emit:

bash
uv run {baseDir}/scripts/yara_lint.py suspect.yar      # style, metadata, YARA-X compatibility
uv run {baseDir}/scripts/atom_analyzer.py suspect.yar  # atom quality per string

They catch the mechanical faults — short strings, FP-prone substrings, unbounded quantifiers, expensive terms ahead of cheap ones — so your attention goes to the judgement calls they cannot make: whether the strings identify this family, and whether the condition can fire on generic strings alone. Report findings by code (E002, W009) so the author can look each one up in style-guide.md.

See testing.md for the validation workflow and rule-development.md for the full step-by-step guide.

Common Mistakes

MistakeBadGood
API names as indicators"VirtualAlloc"Hex pattern of call site + unique mutex
Unbounded regex/https?:\/\/.*//https?:\/\/[a-z0-9]{8,12}\.onion/
Missing file type filterpe.imports(...) firstuint16(0) == 0x5A4D and filesize < 10MB first
Short strings"abc" (3 bytes)"abcdef" (4+ bytes)
Unescaped braces (YARA-X)/config{key}//config\{key\}/
Wrong-endian magic bytesuint32(0) == 0xCAFEBABEuint32be(0) == 0xCAFEBABE

Quality Checklist

Before deploying any rule:

  • Name follows {CATEGORY}_{PLATFORM}_{FAMILY}_{VARIANT}_{DATE}
  • Description starts with "Detects" and explains what/how
  • All required metadata present (author, reference, date)
  • Strings are unique — not API names, common paths, or format strings
  • All strings 4+ bytes with good atom potential
  • Base64 modifier only on strings with 3+ characters
  • Regex bounded, anchored to a literal, with { escaped
  • Condition starts with cheap checks (filesize, magic bytes)
  • Magic-byte constants verified against a known-good sample
  • Rule matches all target samples
  • Rule produces zero matches on the goodware corpus
  • yr check and yr fmt --check pass
  • Linter passes with no errors
  • Peer review completed

Scripts

bash
uv run {baseDir}/scripts/yara_lint.py rule.yar      # validate style/metadata
uv run {baseDir}/scripts/atom_analyzer.py rule.yar  # check string quality

See README.md for detailed script documentation.

Further Reading

TopicDocument
Naming and metadata conventionsstyle-guide.md
Performance and atom optimizationperformance.md
String types and judgmentstrings.md
Testing and validationtesting.md
Chrome extension module (crx)crx-module.md
Android DEX module (dex)dex-module.md
Complete rule development processrule-development.md

The examples/ directory holds real, attributed rules worth reading before writing your own:

ExampleDemonstratesSource
MAL_Win_Remcos_Jan25.yarPE malware: graduated string counts, multiple rules per familyElastic Security
MAL_Mac_ProtonRAT_Jan25.yarmacOS: Mach-O magic bytes, multi-category groupingAirbnb BinaryAlert
MAL_NPM_SupplyChain_Jan25.yarnpm supply chain: real attack patterns, ERC-20 selectorsStairwell Research
SUSP_JS_Obfuscation_Jan25.yarJavaScript: obfuscator detection, density-based matchingimp0rtp3, Nils Kuhnert
SUSP_CRX_SuspiciousPermissions.yarChrome extensions: crx module, permissionsEducational

Rule repositories to learn from: Neo23x0/signature-base (17,000+ production rules), elastic/protections-artifacts (endpoint-tested), imp0rtp3/js-yara-rules (JavaScript), InQuest/awesome-yara (curated index).

Guides: YARA Style Guide and YARA Performance Guidelines (Neo23x0), YARA-X documentation.

macOS specifics: Apple's own production rules ship at /System/Library/CoreServices/XProtect.bundle/; objective-see publishes macOS malware research and samples.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 21 other files (scripts, references, assets) in plugins/yara-authoring/skills/yara-rule-authoring of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • examples/MAL_Mac_ProtonRAT_Jan25.yar
  • examples/MAL_NPM_SupplyChain_Jan25.yar
  • examples/MAL_Win_Remcos_Jan25.yar
  • examples/SUSP_CRX_SuspiciousPermissions.yar
  • examples/SUSP_JS_Obfuscation_Jan25.yar
  • references/crx-module.md
  • references/dex-module.md
  • references/performance.md
  • references/strings.md
  • references/style-guide.md
  • references/testing.md
  • scripts/atom_analyzer.py
  • scripts/pyproject.toml
  • … and 6 more

Open the folder on GitHubat commit 82fe822

Compare with similar skills

YARA-X Rule Authoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

YARA-X Rule Authoring compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
YARA-X Rule Authoring this skilltrailofbits/skills7.4k—~5.9kAutomated safety check: PassCC-BY-SA-4.0
Building Automated Malware Submission Pipelinemukul975/Anthropic-Cybersecurity-Skills34k—~4.7kAutomated safety check: PassApache-2.0
Incident Response NetworkLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassApache-2.0
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT

Similar skills

  • Building Automated Malware Submission Pipeline

    mukul975/Anthropic-Cybersecurity-Skills

    Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and…

    34k GitHub stars~4.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Incident Response Network

    LeoYeAI/openclaw-master-skills

    Network forensics evidence collection and analysis during security incidents.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 2 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Categories

Questions about YARA-X Rule Authoring

What does YARA-X Rule Authoring do?

Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. The skill targets YARA-X, the Rust-based successor to legacy YARA, installed with brew or cargo and run through the yr CLI. Its principles: pick strings that yield good four-byte atoms, aim rules at specific malware families rather than broad categories, test against a goodware corpus before deployment, order cheap checks first (file size, magic bytes, strings, then modules), and treat metadata as documentation of what a rule catches and where the sample came from.

When should I use YARA-X Rule Authoring?

YARA-X Rule Authoring fits situations like: writing a new YARA-X rule for a malware family; reviewing or speeding up an existing ruleset; reducing false positives before putting rules into production; converting legacy YARA rules to YARA-X.

How do I install YARA-X Rule Authoring in Claude Code?

Run `npx skills add trailofbits/skills --skill yara-rule-authoring -a claude-code`. Or copy the skill folder (plugins/yara-authoring/skills/yara-rule-authoring in trailofbits/skills) into .claude/skills/yara-rule-authoring in your project. Claude Code loads it when a task matches its description.

How do I install YARA-X Rule Authoring in Codex?

Run `npx skills add trailofbits/skills --skill yara-rule-authoring -a codex`. Or copy the skill folder (plugins/yara-authoring/skills/yara-rule-authoring in trailofbits/skills) into .agents/skills/yara-rule-authoring in your project. Codex loads it when a task matches its description.

Can I use YARA-X Rule Authoring in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill yara-rule-authoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/yara-rule-authoring, .gemini/skills/yara-rule-authoring, .github/skills/yara-rule-authoring and .opencode/skills/yara-rule-authoring in your project.

What does YARA-X Rule Authoring need to run?

Going by SKILL.md and its folder, YARA-X Rule Authoring needs Python for the scripts in its folder and the command-line tools its instructions call (uv, brew, cargo and ssh). Our summary lists: YARA-X, installed with brew install yara-x or cargo install yara-x.

Does YARA-X Rule Authoring access the network?

SKILL.md names 3 domains. As links in the text: github.com, virustotal.github.io and objective-see.org. This is read from the text; nothing was executed.

Is YARA-X Rule Authoring safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does YARA-X Rule Authoring use?

YARA-X Rule Authoring is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does YARA-X Rule Authoring use?

About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to YARA-X Rule Authoring?

Skills that share tags, products or a category with YARA-X Rule Authoring: Building Automated Malware Submission Pipeline (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Incident Response Network (LeoYeAI/openclaw-master-skills, 2.2k stars), vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars) and Webhome Extension Builder (webhtv/webhtv, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains YARA-X Rule Authoring?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.