How it works
A YARA rule has a name, optional metadata, a set of strings to look for (plain text, hex byte patterns or regular expressions) and a condition such as 'any two of these strings, in a file smaller than 1 MB'. Analysts write rules after studying a sample, often with reverse engineering, and share them so others can find the same family even when file hashes differ. Antivirus engines, incident responders, VirusTotal and many security products run YARA rules.
YARA was created at VirusTotal and is free and open source. YARA-X, a rewrite in Rust by the same team, became the stable successor in 2025 and runs most existing rules unchanged, while the original YARA now receives only bug fixes. Rules are not limited to malware: they can match any file with recognisable content.
YARA rules pricing
Open source
Free (BSD 3-Clause), for both YARA and YARA-X.
Approximate, checked September 2026.What the other tools cost
Related terms
More in Security
Testing and research