Skip to main content
Glama
Heretek-RE

re-yara

by Heretek-RE

re-yara

MCP server wrapping the YARA pattern-matching engine for binary triage.

re-yara is intentionally rule-agnostic: the server compiles whatever rule directory the analyst points it at, then scans files or directories against the compiled rules. No rules are bundled with the plugin — YARA rules describe categories of binary behaviour (e.g. encrypted-VM bytecode interpreter dispatcher, MBA-obfuscated arithmetic routine, legacy disc-based protection handshake) and writing them is an analyst decision, not a plugin one.

Tools

Tool

What it does

check_yara

Health check — return YARA version + whether yara-python is importable

compile_rules

Compile all *.yar / *.yara files under a directory into a YARA ruleset

scan_binary

Run a compiled ruleset against a single file

scan_directory

Walk a directory and run the compiled ruleset against every file

Related MCP server: secureaudit-mcp

Install

Part of the RE-AI plugin; ./install.sh installs the package. To install standalone:

pip install -e ./servers/re-yara

Requires the yara C library (libyara) at runtime — yara-python links against it. Most package managers ship yara as a system package; on Debian/Ubuntu:

sudo apt-get install yara libyara-dev

Run

re-yara                           # stdio transport (default for MCP)
python -m re_yara                 # equivalent

Workflow

  1. Author or download a directory of *.yar files. Each rule describes a category of behaviour the analyst wants to find.

  2. Call compile_rules(rules_dir=<path>) to validate + compile.

  3. Call scan_binary(path=<file>, rules_dir=<path>) for a single file, or scan_directory(path=<dir>, rules_dir=<path>) for a whole tree.

compile_rules is the heavy step (parses every rule file). The scan tools re-compile as needed — they're cheap if the rules haven't changed.

Why no bundled rules

YARA rules are an analyst artefact: they describe what you are looking for, which is a question only the user can answer. The plugin gives the engine; the user brings the policies. The server is also compatible with the signature-base and [MalwareBazaar] rule collections — point rules_dir at any of them.

A
license - permissive license
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    A Model Context Protocol server that enables AI assistants to perform YARA rule-based threat analysis on files and URLs, supporting comprehensive rule management and detailed scanning results.
    23
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An AppSec-focused MCP server that performs static analysis scans on C/C++ source code for memory-safety vulnerabilities and parses compiled PE/ELF binary headers locally to audit active defensive compiler mitigations (ASLR, DEP/NX, PIE).
    4
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server exposing LIEF for cross-format binary analysis, enabling parsing, section listing, imports/exports, disassembly, and string extraction for PE, ELF, MachO, DEX, ART, and OAT files.
    17
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for ScanMalware.com URL scanning, malware detection, and analysis.

  • VirusTotal MCP — file / URL / domain / IP reputation (BYO key)

  • A paid remote MCP for developer endpoint scanner MCP, built to return verdicts, receipts, usage logs

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Heretek-RE/re-yara'

If you have feedback or need assistance with the MCP directory API, please join our Discord server