← All Tools
YARA Rule Builder & Tester
Build YARA detection rules visually with a live preview, validate the syntax, and run a quick string-match test against pasted samples.
100% client-side. No samples, rules, or text are sent to any server. No storage, no cookies, no tracking.
Metadata
Strings
Examples: any of them, all of them, 2 of ($s*), $s1 and $s2, filesize < 1MB and any of them.
YAR Preview
Quick Tester
Paste a sample (log line, command line, decoded payload, etc.). The tester runs your text and regex strings against the sample and evaluates a subset of conditions client-side. Hex strings are decoded as raw bytes via UTF-8 only when comparing.
YARA syntax reference
- Modifiers on text strings:
nocase,wide,ascii,fullword,xor,base64,private. - Hex strings support wildcards (
?), jumps ([2-4]), and alternations ((AA|BB)). - Conditions can reference
filesize,uint16(0)for MZ/ELF magic, and counts via#s1 > 2. - Always set
filesizebounds for performance:filesize < 5MB and any of them.