S2W Quaxar

Download 91
Last updated Mar 10, 2026

quaxar-yara-rules

List YARA detection rules from S2W Quaxar service.

Syntax

quaxar-yara-rules [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] [actors=ACTORS] [malwares=MALWARES] [authors=AUTHORS] [pretty=PRETTY]

Options

profile=PROFILE
Optional. QUAXAR connect profile code
duration=NUM{mon|w|d|h|m|s}
Optional. Scan only recent data. Use s(second), m(minute), h(hour), d(day), mon(month) time unit.
from=yyyyMMddHHmmss
Optional. Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
Optional. End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
actors=ACTORS
Optional. Comma-separated threat actor filter.
malwares=MALWARES
Optional. Comma-separated malware filter.
authors=AUTHORS
Optional. Comma-separated author filter.
pretty=PRETTY
Optional. Set t to enable pretty print with line breaks (default: f).

Output Fields

FieldTypeNameDescription
profileStringConnect profileProfile name of QUAXAR
idStringIDSIGV rule ID
typeStringTypeDetection rule type
nameStringNameRule name
descriptionStringDescription
createdDateCreatedCreation time
modifiedDateModifiedLast modified time
authorStringAuthorRule author
patternStringPatternDetection pattern
threat_actorsStringThreat actorsNewline-separated names
malwaresStringMalwaresNewline-separated names
campaignsStringCampaignsNewline-separated names
quaxar_linksStringQXR linksNewline-separated URLs
referencesStringReferencesNewline-separated references