CompTIA CySA+ (CS0-003)Security OperationsMedium
A malware analyst wants to write reusable detection signatures based on specific byte sequences, strings, and file structure patterns so that antivirus and EDR tools can scan disk and memory for known malware families across many samples. Which tool/format is purpose-built for this task?
- ASigma rule
- BYARA rule
- CSnort signature
- DSuricata rule
Show answer & explanationAnswer & explanation
Correct answer: B. YARA rule
YARA rules are designed specifically to identify and classify malware by matching binary or textual patterns within files or memory, making them ideal for malware family detection. Snort and Suricata signatures detect malicious network traffic, and Sigma rules describe generic log-based detection logic for SIEMs.
Why the other options are wrong
- A. Sigma rules are generic, SIEM-agnostic log detection queries, not file pattern matching.
- C. Snort signatures inspect network packets, not file content.
- D. Suricata signatures, like Snort, focus on network traffic inspection.
YARA Rule
A rule-based language used to identify and classify malware samples by matching strings, byte patterns, and structural conditions within files or memory.
- Rules contain strings section and a condition section
- Used by antivirus, EDR, and sandbox tools for classification
- Different purpose from network IDS signatures (Snort/Suricata)
Memory trick: 'YARA hunts inside files, Snort hunts inside packets.'