← All Tools

🔭 YARA Rule Builder & Tester

Build YARA detection rules visually with a live preview, validate the syntax, and run a quick string-match test against pasted samples.

100% client-side. No samples, rules, or text are sent to any server. No storage, no cookies, no tracking.

Metadata

Strings

Examples: any of them, all of them, 2 of ($s*), $s1 and $s2, filesize < 1MB and any of them.

YAR Preview


                    

Quick Tester

Paste a sample (log line, command line, decoded payload, etc.). The tester runs your text and regex strings against the sample and evaluates a subset of conditions client-side. Hex strings are decoded as raw bytes via UTF-8 only when comparing.

YARA syntax reference

  • Modifiers on text strings: nocase, wide, ascii, fullword, xor, base64, private.
  • Hex strings support wildcards (?), jumps ([2-4]), and alternations ((AA|BB)).
  • Conditions can reference filesize, uint16(0) for MZ/ELF magic, and counts via #s1 > 2.
  • Always set filesize bounds for performance: filesize < 5MB and any of them.