Security · Tool

YARA rules

A simple rule language for describing what a family of malware, or any other kind of file, looks like, so scanners can spot matching files on disks, in memory or among uploads.

Testing and research · Open source · updated

How it works

A YARA rule has a name, optional metadata, a set of strings to look for (plain text, hex byte patterns or regular expressions) and a condition such as 'any two of these strings, in a file smaller than 1 MB'. Analysts write rules after studying a sample, often with reverse engineering, and share them so others can find the same family even when file hashes differ. Antivirus engines, incident responders, VirusTotal and many security products run YARA rules.

YARA was created at VirusTotal and is free and open source. YARA-X, a rewrite in Rust by the same team, became the stable successor in 2025 and runs most existing rules unchanged, while the original YARA now receives only bug fixes. Rules are not limited to malware: they can match any file with recognisable content.

YARA rules pricing

Open source

Free (BSD 3-Clause), for both YARA and YARA-X.

Approximate, checked September 2026.What the other tools cost

More in Security

Testing and research

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.