Skip to content
corelightPublic

About

A desktop workbench for writing, validating, compiling, and testing YARA rules.

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

Quipu logo
Quipu

A desktop workbench for writing, validating, compiling, and testing YARA rules.

CI status CodeQL status

Quipu (pronounced “KEE-poo”) brings a project explorer, a YARA-aware editor, the YARA-X compiler, and focused scan results into one local application. It embeds both YARA-X and its language server, so you do not need a separate YARA installation.

Important

Quipu is at MVP stage. Builds target Linux and Windows x86-64. Windows desktop validation covers Windows 11 24H2; see the validation record. Experimental macOS builds have CI coverage and user-confirmed build validation; see the validation record.

Quipu showing a compiled YARA project and two matching scan results

Features

  • Open a folder of .yar and .yara files as a workspace, or start with a scratch rule.
  • Explore inferred or configured entrypoints, nested includes, external includes, and project problems.
  • Edit with Monaco syntax highlighting, completion, hover documentation, and live YARA-X diagnostics.
  • Compile a complete workspace, then scan typed text or a selected file.
  • Inspect matching rules, patterns, offsets, byte lengths, and highlighted bytes in a hex viewer.
  • Jump from diagnostics and matches directly to their source definitions.
  • Restore unchanged compiled rulesets from a bounded local cache.
  • Work from a set of small, self-contained example projects included with the application.

Rules and scan targets are processed locally. Quipu does not send their contents to a remote service.

Install on Linux

Linux x86-64 packages are published on the GitHub Releases page:

Package Best for Install or run
AppImage Portable use on supported distributions chmod +x Quipu_*.AppImage && ./Quipu_*.AppImage
.deb Ubuntu 22.04+ and Debian 12+ sudo apt install ./Quipu_*.deb
.rpm Recent Fedora releases sudo dnf install ./Quipu-*.rpm

The .deb and .rpm packages use the system WebKitGTK runtime. If your distribution cannot satisfy that dependency, use the AppImage.

Development packages are available as quipu-linux-x86_64 artifacts from successful CI runs. CI and Release call the same Linux workflow, including package validation and native menu smoke tests. The combined SHA256SUMS file is supplied by Release, not by individual CI artifacts.

Quipu packages are not currently signed. Each release includes a SHA256SUMS file; download it beside the packages and verify the files you downloaded with:

sha256sum --ignore-missing --check SHA256SUMS

The checksums detect accidental corruption but are not an authenticated signature.

Install on Windows

For Windows x86-64 packages (v0.3.0 and later), download an installer from GitHub Releases. Development builds are also available as quipu-windows-x86_64 artifacts from successful CI runs.

  • Use the NSIS .exe installer for a current-user installation.
  • An MSI .msi installer is also available.
  • Microsoft Edge WebView2 is required. The installer downloads its bootstrapper if the runtime is missing, so installation may need internet access.

The installers are unsigned, so Windows may show an unknown-publisher or SmartScreen warning. Check that your download came from this repository's release or workflow before proceeding.

Release packages include a combined SHA256SUMS file. In PowerShell, calculate the hash of your downloaded installer (replace the example filename):

Get-FileHash -Algorithm SHA256 .\Quipu_VERSION_x64-setup.exe
Get-Content .\SHA256SUMS

Compare the hash with the entry for that exact filename, ignoring letter case. Individual CI artifacts do not include the combined release checksum file.

If a compiled ruleset is forgotten after restarting, check the bundled guide's Windows Defender troubleshooting. It explains how to confirm a quarantine and, if needed, exclude only the cache directory.

Experimental macOS builds

The CI workflow builds ad-hoc signed DMGs for Apple Silicon and Intel, targeting macOS 15 or newer. They do not require an Apple Developer membership to build, but are not notarized and may require a Gatekeeper override to launch. See macOS development for CI artifacts, build instructions, and the current validation status.

Quick start

  1. Start Quipu and choose File → Open Example… → Basic text match.
  2. Explore text_indicators.yar in the editor.
  3. Choose Rules → Compile Workspace or press Ctrl+Shift+B.
  4. Scan the prepared target with Rules → Scan Target or press Ctrl+Shift+Enter.
  5. Expand a match and select it to inspect the highlighted bytes.

The full guide is bundled with Quipu under Help → Documentation. Its source is also available in documentation/content.

Workspaces and quipu.toml

Without configuration, Quipu recursively discovers rule files and infers an entrypoint from each file that is not included by another file. Add a quipu.toml at the workspace root when you need explicit entrypoints, include directories, or exclusions:

schema = 1
entrypoints = ["main.yar"]
include_dirs = ["rules", "../shared-rules"]
exclude = ["fixtures/**", "vendor/legacy/**"]

See Workspaces and projects for the complete project model and manifest reference.

Build from source

All platforms need:

  • Rust 1.93 or newer
  • Node.js 22.12 or newer
  • Zola 0.23.6
  • Git

For Windows, follow Windows development for the MSVC build tools, Windows SDK, WebView2 runtime, and PowerShell build commands.

For experimental macOS builds, follow macOS development.

Linux also needs the native libraries required by Tauri and WebKitGTK.

On Debian or Ubuntu, install the native dependencies with:

sudo apt update
sudo apt install -y \
  build-essential \
  curl \
  file \
  libayatana-appindicator3-dev \
  libgtk-3-dev \
  librsvg2-dev \
  libssl-dev \
  libwebkit2gtk-4.1-dev \
  patchelf \
  rpm \
  wget

Then build all three Linux package formats:

git clone https://github.com/corelight/quipu.git
cd quipu/app
npm ci
npm run tauri -- build --bundles appimage,deb,rpm

Artifacts are written below app/src-tauri/target/release/bundle/. The first build can take a while because Cargo compiles YARA-X and its dependencies from source.

Windows build setup, installer behavior, and filesystem limitations are described in Windows development.

Develop and test

Install dependencies and start the development application:

cd app
npm ci
npm run tauri -- dev

Run the frontend unit tests, production frontend build, and Rust tests with:

cd app
npm test
npm run build

cd src-tauri
cargo test --locked

The native-menu acceptance suite has additional Linux display-server requirements. See test/README.md for its setup and usage.

Architecture

Quipu is a Tauri application with a vanilla TypeScript frontend and a Rust backend:

  • Vite bundles the frontend and Monaco editor into the application webview.
  • Tauri IPC connects the UI to workspace, filesystem, compilation, cache, and scanning services in Rust.
  • The YARA-X compiler and language server run in-process.
  • Zola builds an offline documentation site that is embedded in the app.
app/src/           TypeScript frontend
app/src-tauri/     Rust backend and desktop packaging
documentation/    Source for the bundled offline guide
examples/          Projects bundled with the application
test/ui/           Native-menu acceptance test harness

The application version is defined in app/package.json; Tauri reads that value when it names packages and reports the running version.

Current limitations

  • Release packages target Linux and Windows x86-64. macOS Apple Silicon and Intel builds remain experimental CI artifacts; see the macOS validation record.
  • Quipu scans one selected file or one text buffer at a time, not directories or batches.
  • New rules are created at the workspace root. Move and delete operations are performed outside Quipu.
  • A scratch rule can be compiled and scanned, but not saved or cached.

Contributing and security

Contributions are welcome. Read CONTRIBUTING.md before opening a pull request.

Please do not report security vulnerabilities in a public issue. Follow the private reporting process in SECURITY.md.

Acknowledgements

Quipu is built by Corelight and powered by YARA-X, Monaco Editor, and Tauri.

License

Quipu is distributed under the 3-clause BSD license. See LICENSE. Notices for software incorporated from third parties are in THIRD_PARTY_LICENSES.

About

A desktop workbench for writing, validating, compiling, and testing YARA rules.

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages