pub struct SigSet { /* private fields */ }Expand description
A set of compiled YARA signatures for malware detection.
SigSet wraps compiled YARA rules and can be cheaply cloned due to internal
use of Arc. It provides a fluent builder API for constructing signature sets
from individual rules, directories, or recursive directory trees.
§Examples
use open_detect::{SigSet, Signature};
use std::path::Path;
// From a single signature
let sig_set = SigSet::from_signature(
Signature("rule test { condition: true }".to_string())
).unwrap();
// From a directory
let sig_set = SigSet::new()
.with_sig_dir(Path::new("signatures"))
.unwrap();
// Chain multiple sources
let sig_set = SigSet::from_signature(
Signature("rule manual { condition: true }".to_string())
)
.unwrap()
.with_sig_dir_recursive(Path::new("signatures"))
.unwrap();Implementations§
Source§impl SigSet
impl SigSet
Sourcepub fn new() -> Self
pub fn new() -> Self
Create a new empty SigSet with no signatures.
This is useful as a starting point for the builder pattern.
§Examples
use open_detect::SigSet;
let sig_set = SigSet::new();
assert_eq!(sig_set.count(), 0);Sourcepub fn from_signature(signature: Signature) -> Result<Self>
pub fn from_signature(signature: Signature) -> Result<Self>
Sourcepub fn from_signatures(signatures: Vec<Signature>) -> Result<Self>
pub fn from_signatures(signatures: Vec<Signature>) -> Result<Self>
Create a SigSet from multiple YARA signatures.
§Errors
Returns an error if any signature fails to compile.
§Examples
use open_detect::{SigSet, Signature};
let sig_set = SigSet::from_signatures(vec![
Signature("rule test1 { condition: true }".to_string()),
Signature("rule test2 { condition: false }".to_string()),
]).unwrap();
assert_eq!(sig_set.count(), 2);Sourcepub fn with_signature(self, signature: Signature) -> Result<Self>
pub fn with_signature(self, signature: Signature) -> Result<Self>
Add a single signature to this SigSet, returning a new SigSet.
This recompiles all signatures including the new one.
§Errors
Returns an error if signature compilation fails.
§Examples
use open_detect::{SigSet, Signature};
let sig_set = SigSet::new()
.with_signature(Signature("rule test { condition: true }".to_string()))
.unwrap();
assert_eq!(sig_set.count(), 1);Sourcepub fn with_signatures(self, new_signatures: Vec<Signature>) -> Result<Self>
pub fn with_signatures(self, new_signatures: Vec<Signature>) -> Result<Self>
Add multiple signatures to this SigSet, returning a new SigSet.
This recompiles all signatures including the new ones.
§Errors
Returns an error if signature compilation fails.
§Examples
use open_detect::{SigSet, Signature};
let sig_set = SigSet::new()
.with_signatures(vec![
Signature("rule test1 { condition: true }".to_string()),
Signature("rule test2 { condition: false }".to_string()),
])
.unwrap();
assert_eq!(sig_set.count(), 2);Sourcepub fn with_sig_dir(self, path: &Path) -> Result<Self>
pub fn with_sig_dir(self, path: &Path) -> Result<Self>
Add all YARA files from a directory (non-recursive).
Loads files with extensions: .yar, .yara, .yrc
§Errors
Returns an error if:
- The directory cannot be read
- Any signature file cannot be read
- Signature compilation fails
§Examples
use open_detect::SigSet;
use std::path::Path;
let sig_set = SigSet::new()
.with_sig_dir(Path::new("signatures"))
.unwrap();Sourcepub fn with_sig_dir_recursive(self, path: &Path) -> Result<Self>
pub fn with_sig_dir_recursive(self, path: &Path) -> Result<Self>
Add all YARA files from a directory recursively.
Recursively traverses subdirectories and loads all files with
extensions: .yar, .yara, .yrc
§Errors
Returns an error if:
- The directory cannot be read
- Any signature file cannot be read
- Signature compilation fails
§Examples
use open_detect::SigSet;
use std::path::Path;
let sig_set = SigSet::new()
.with_sig_dir_recursive(Path::new("signatures"))
.unwrap();Trait Implementations§
Auto Trait Implementations§
impl Freeze for SigSet
impl !RefUnwindSafe for SigSet
impl Send for SigSet
impl Sync for SigSet
impl Unpin for SigSet
impl !UnwindSafe for SigSet
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.