re-yara
MCP server wrapping the YARA pattern-matching engine for binary triage, enabling users to compile and scan files against analyst-defined YARA rules.
README
re-yara
MCP server wrapping the YARA pattern-matching engine for binary triage.
re-yara is intentionally rule-agnostic: the server compiles
whatever rule directory the analyst points it at, then scans files
or directories against the compiled rules. No rules are bundled
with the plugin — YARA rules describe categories of binary
behaviour (e.g. encrypted-VM bytecode interpreter dispatcher,
MBA-obfuscated arithmetic routine, legacy disc-based protection
handshake) and writing them is an analyst decision, not a plugin
one.
Tools
| Tool | What it does |
|---|---|
check_yara |
Health check — return YARA version + whether yara-python is importable |
compile_rules |
Compile all *.yar / *.yara files under a directory into a YARA ruleset |
scan_binary |
Run a compiled ruleset against a single file |
scan_directory |
Walk a directory and run the compiled ruleset against every file |
Install
Part of the RE-AI plugin; ./install.sh installs the package. To
install standalone:
pip install -e ./servers/re-yara
Requires the yara C library (libyara) at runtime — yara-python
links against it. Most package managers ship yara as a system
package; on Debian/Ubuntu:
sudo apt-get install yara libyara-dev
Run
re-yara # stdio transport (default for MCP)
python -m re_yara # equivalent
Workflow
- Author or download a directory of
*.yarfiles. Each rule describes a category of behaviour the analyst wants to find. - Call
compile_rules(rules_dir=<path>)to validate + compile. - Call
scan_binary(path=<file>, rules_dir=<path>)for a single file, orscan_directory(path=<dir>, rules_dir=<path>)for a whole tree.
compile_rules is the heavy step (parses every rule file). The
scan tools re-compile as needed — they're cheap if the rules
haven't changed.
Why no bundled rules
YARA rules are an analyst artefact: they describe what you are
looking for, which is a question only the user can answer. The
plugin gives the engine; the user brings the policies. The
server is also compatible with the signature-base and
[MalwareBazaar] rule collections — point rules_dir at any of
them.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.