logo

Arya: The New Tailor-Made EICAR Using Yara

ID: d81bdc1c-9e47-5dd0-b125-e4501c4f5e00

STIX ID: report--d81bdc1c-9e47-5dd0-b125-e4501c4f5e00

Feed Name: Claroty Team82

Date Published: 2023-08-15

Date Updated: 2026-04-17

Author: Bar Ofner

...
...

This report presents Arya, a tool that parses YARA rules (via yaramod) and synthesizes pseudo‑malicious files containing strings, byte sequences, PE headers, and x86 code to deliberately trigger YARA, antivirus, and EDR detections for research, rule QA, and purple‑teaming. It describes Arya's architecture (AST traversal, mapping and placer components), supported features, limitations, and intended use for testing detection pipelines rather than describing an active cyber incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.