YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns.
... part of T2, get it here
URL: https://virustotal.github.io/yara/
Author: Avast
Author: Google Inc.
Author: Hilko Bengen <bengen [at] hilluzination [dot] de>
Author: Joachim Metz <joachim [dot] metz [at] gmail [dot] com>
Author: Stefan Buehlmann <stefan [dot] buehlmann [at] joebox [dot] org>
Author: Victor M. Alvarez <plusvic [at] gmail [dot] com>;<vmalvarez [at] virustotal [dot] com>
Author: Wesley Shields <wxs [at] atarininja [dot] org>
Maintainer: The T2 Project <t2 [at] t2-project [dot] org>
License: BSD
Status: Stable
Version: 4.5.2
Remark: Does cross compile (as setup and patched in T2).
Download: https://github.com/VirusTotal/yara/ yara-4.5.2.tar.gz
T2 source: yara.cache
T2 source: yara.desc
Build time (on reference hardware): 10% (relative to binutils)2
Installed size (on reference hardware): 1.81 MB, 50 files
Dependencies (build time detected): 00-dirtree autoconf automake bash binutils coreutils diffutils file findutils gawk grep gzip jansson libtool linux-header m4 make openssl perl sed tar
Installed files (on reference hardware): n.a.
1) This page was automatically generated from the T2 package source. Corrections, such as dead links, URL changes or typos need to be performed directly on that source.
2) Compatible with Linux From Scratch's "Standard Build Unit" (SBU).