A desktop workbench for writing, validating, compiling, and testing YARA rules.
Quipu (pronounced “KEE-poo”) brings a project explorer, a YARA-aware editor, the YARA-X compiler, and focused scan results into one local application. It embeds both YARA-X and its language server, so you do not need a separate YARA installation.
Important
Quipu is at MVP stage. Builds target Linux and Windows x86-64. Windows desktop validation covers Windows 11 24H2; see the validation record. Experimental macOS builds have CI coverage and user-confirmed build validation; see the validation record.
- Open a folder of
.yarand.yarafiles as a workspace, or start with a scratch rule. - Explore inferred or configured entrypoints, nested includes, external includes, and project problems.
- Edit with Monaco syntax highlighting, completion, hover documentation, and live YARA-X diagnostics.
- Compile a complete workspace, then scan typed text or a selected file.
- Inspect matching rules, patterns, offsets, byte lengths, and highlighted bytes in a hex viewer.
- Jump from diagnostics and matches directly to their source definitions.
- Restore unchanged compiled rulesets from a bounded local cache.
- Work from a set of small, self-contained example projects included with the application.
Rules and scan targets are processed locally. Quipu does not send their contents to a remote service.
Linux x86-64 packages are published on the GitHub Releases page:
| Package | Best for | Install or run |
|---|---|---|
| AppImage | Portable use on supported distributions | chmod +x Quipu_*.AppImage && ./Quipu_*.AppImage |
.deb |
Ubuntu 22.04+ and Debian 12+ | sudo apt install ./Quipu_*.deb |
.rpm |
Recent Fedora releases | sudo dnf install ./Quipu-*.rpm |
The .deb and .rpm packages use the system WebKitGTK runtime. If your
distribution cannot satisfy that dependency, use the AppImage.
Development packages are available as quipu-linux-x86_64 artifacts from
successful CI runs.
CI and Release call the same Linux workflow, including package validation and
native menu smoke tests. The combined SHA256SUMS file is supplied by Release,
not by individual CI artifacts.
Quipu packages are not currently signed. Each release includes a
SHA256SUMS file; download it beside the packages and verify the files you
downloaded with:
sha256sum --ignore-missing --check SHA256SUMSThe checksums detect accidental corruption but are not an authenticated signature.
For Windows x86-64 packages (v0.3.0 and later), download an installer from
GitHub Releases.
Development builds are also available as quipu-windows-x86_64 artifacts from
successful CI runs.
- Use the NSIS
.exeinstaller for a current-user installation. - An MSI
.msiinstaller is also available. - Microsoft Edge WebView2 is required. The installer downloads its bootstrapper if the runtime is missing, so installation may need internet access.
The installers are unsigned, so Windows may show an unknown-publisher or SmartScreen warning. Check that your download came from this repository's release or workflow before proceeding.
Release packages include a combined SHA256SUMS file. In PowerShell, calculate
the hash of your downloaded installer (replace the example filename):
Get-FileHash -Algorithm SHA256 .\Quipu_VERSION_x64-setup.exe
Get-Content .\SHA256SUMSCompare the hash with the entry for that exact filename, ignoring letter case. Individual CI artifacts do not include the combined release checksum file.
If a compiled ruleset is forgotten after restarting, check the bundled guide's Windows Defender troubleshooting. It explains how to confirm a quarantine and, if needed, exclude only the cache directory.
The CI workflow builds ad-hoc signed DMGs for Apple Silicon and Intel, targeting macOS 15 or newer. They do not require an Apple Developer membership to build, but are not notarized and may require a Gatekeeper override to launch. See macOS development for CI artifacts, build instructions, and the current validation status.
- Start Quipu and choose File → Open Example… → Basic text match.
- Explore
text_indicators.yarin the editor. - Choose Rules → Compile Workspace or press Ctrl+Shift+B.
- Scan the prepared target with Rules → Scan Target or press Ctrl+Shift+Enter.
- Expand a match and select it to inspect the highlighted bytes.
The full guide is bundled with Quipu under Help → Documentation. Its source
is also available in documentation/content.
Without configuration, Quipu recursively discovers rule files and infers an
entrypoint from each file that is not included by another file. Add a
quipu.toml at the workspace root when you need explicit entrypoints, include
directories, or exclusions:
schema = 1
entrypoints = ["main.yar"]
include_dirs = ["rules", "../shared-rules"]
exclude = ["fixtures/**", "vendor/legacy/**"]See Workspaces and projects for the complete project model and manifest reference.
All platforms need:
- Rust 1.93 or newer
- Node.js 22.12 or newer
- Zola 0.23.6
- Git
For Windows, follow Windows development for the MSVC build tools, Windows SDK, WebView2 runtime, and PowerShell build commands.
For experimental macOS builds, follow macOS development.
Linux also needs the native libraries required by Tauri and WebKitGTK.
On Debian or Ubuntu, install the native dependencies with:
sudo apt update
sudo apt install -y \
build-essential \
curl \
file \
libayatana-appindicator3-dev \
libgtk-3-dev \
librsvg2-dev \
libssl-dev \
libwebkit2gtk-4.1-dev \
patchelf \
rpm \
wgetThen build all three Linux package formats:
git clone https://github.com/corelight/quipu.git
cd quipu/app
npm ci
npm run tauri -- build --bundles appimage,deb,rpmArtifacts are written below app/src-tauri/target/release/bundle/. The first
build can take a while because Cargo compiles YARA-X and its dependencies from
source.
Windows build setup, installer behavior, and filesystem limitations are described in Windows development.
Install dependencies and start the development application:
cd app
npm ci
npm run tauri -- devRun the frontend unit tests, production frontend build, and Rust tests with:
cd app
npm test
npm run build
cd src-tauri
cargo test --lockedThe native-menu acceptance suite has additional Linux display-server
requirements. See test/README.md for its setup and usage.
Quipu is a Tauri application with a vanilla TypeScript frontend and a Rust backend:
- Vite bundles the frontend and Monaco editor into the application webview.
- Tauri IPC connects the UI to workspace, filesystem, compilation, cache, and scanning services in Rust.
- The YARA-X compiler and language server run in-process.
- Zola builds an offline documentation site that is embedded in the app.
app/src/ TypeScript frontend
app/src-tauri/ Rust backend and desktop packaging
documentation/ Source for the bundled offline guide
examples/ Projects bundled with the application
test/ui/ Native-menu acceptance test harness
The application version is defined in app/package.json; Tauri reads that
value when it names packages and reports the running version.
- Release packages target Linux and Windows x86-64. macOS Apple Silicon and Intel builds remain experimental CI artifacts; see the macOS validation record.
- Quipu scans one selected file or one text buffer at a time, not directories or batches.
- New rules are created at the workspace root. Move and delete operations are performed outside Quipu.
- A scratch rule can be compiled and scanned, but not saved or cached.
Contributions are welcome. Read CONTRIBUTING.md before
opening a pull request.
Please do not report security vulnerabilities in a public issue. Follow the
private reporting process in SECURITY.md.
Quipu is built by Corelight and powered by YARA-X, Monaco Editor, and Tauri.
Quipu is distributed under the 3-clause BSD license. See LICENSE.
Notices for software incorporated from third parties are in
THIRD_PARTY_LICENSES.
