Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
yara-x — Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and classify malware families across files. | Kitploit
Tools/GitHubGitHub/virustotal/yara-x
Defensive ToolsDisk ForensicsIndicator of Compromise (IOC) ManagementStatic AnalysisDynamic Analysis (Sandboxing)Memory ForensicsThreat Feeds & AggregatorsVulnerability AnalysisForensicsMobile ForensicsNetwork SecurityData Recovery
1.2k14712h 1m agoReviewed by Kitploit
Malware Analysis
Binary Analysis
Threat Intelligence
Incident Response
Email Security
Top in Data Recovery #19
Top in Defensive Tools #12
Top in Disk Forensics #19
Top in Dynamic Analysis (Sandboxing) #13
Top in Email Security #9
Top in Incident Response #14
Top in Indicator of Compromise (IOC) Management #9
Top in Malware Analysis #1
Top in Memory Forensics #12
Top in Mobile Forensics #19
Top in Network Security #14
Top in Static Analysis #3
Top in Threat Feeds & Aggregators #16
Top in Threat Intelligence #11
GitHubvirustotal/yara-x

yara-x

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and classify malware families across files.

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

tests coverage Crates.io Crates.io MSRV

YARA-X

YARA-X is a re-incarnation of YARA, a pattern matching tool designed with malware researchers in mind. This new incarnation intends to be faster, safer and more user-friendly than its predecessor. The ultimate goal of YARA-X is replacing YARA as the default pattern matching tool for malware researchers.

With YARA-X you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description (a.k.a. rule) consists of a set of patterns and a boolean expression which determine its logic. Let’s see an example:

root@kitploit:~
rule silent_banker : banker {
    meta:
        description = "This is just an example"
        threat_level = 3
        in_the_wild = true

    strings:
        $a = {6A 40 68 00 30 00 00 6A 14 8D 91}
        $b = {8D 4D B0 2B C1 83 C0 27 99 6A 4E 59 F7 F9}
        $c = "UVODFRYSIHLNWPEJXQZAKCBGMT"

    condition:
        $a or $b or $c
}

The above rule is telling YARA-X that any file containing one of the three patterns must be reported as silent_banker. This is just a simple example, more complex and powerful rules can be created by using wild-cards, case-insensitive strings, regular expressions, special operators and many other features that you'll find explained in the documentation.

FAQ

How does YARA-X compare to YARA?

Read this.

Which are the differences at the rule level?

Read this.

Is YARA still maintained?

Yes, it is. YARA is still being maintained, and future releases will include bug fixes and minor features. However, don’t expect new large features or modules. All efforts to enhance YARA, including the addition of new modules, will now focus on YARA-X.

What's the current state of YARA-X?

YARA-X is already mature and stable. At VirusTotal, we have been running YARA-X in production for a long time, scanning billions of files with tens of thousands of rules, and addressing discrepancies and bugs. This means that YARA-X is already battle-tested.

Please test YARA-X and don’t hesitate to open an issue if you find a bug or some feature that you want to see implemented.

Contributing

Contributions to YARA-X are welcome! For details on the Google Contributor License Agreement (CLA) requirement, code style conventions, and how to submit pull requests, please read CONTRIBUTING.md.

Download Tool