virustotal/yara

The pattern matching swiss knife

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 24 minutes ago
Added to GitGenius on September 6th, 2026
Created on December 6th, 2012
Open Issues & Pull Requests: 169 (+0)
GitHub issues: Enabled
Number of forks: 1,583
Total Stargazers: 9,851 (+1)
Total Subscribers: 323 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 2.1 days
Mean response time: 179.5 days
90th percentile: 810.5 days
Tracked items: 59

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 12% of issues opened in the past year have been closed. Three people close 83% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 8
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 1,248 days
Stale 30+ days: 8
Stale 90+ days: 7

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • bug (30)
  • feature-request (12)
  • wontfix (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

YARA is a pattern matching engine designed for malware research and detection.

YARA addresses the problem of identifying and classifying malicious files by providing a rule-based system for pattern matching. Researchers and security analysts write rules in YARA's domain-specific language to describe patterns characteristic of malware, suspicious behavior, or other file properties. The engine then scans files or processes against these rules to identify matches. This approach allows security teams to encode knowledge about threats into reusable, shareable rules that can be applied across large datasets or integrated into automated detection pipelines.

Organizations conducting malware analysis, incident response, or building security infrastructure should consider YARA if they need flexible, rule-driven detection capabilities. The tool suits projects where analysts want to express complex pattern logic without writing custom code for each detection scenario. YARA's rule format enables collaboration within security communities, as rules can be shared, versioned, and refined collectively. It is particularly valuable in environments where detection logic must evolve rapidly in response to emerging threats.

The project maintains active development with regular updates addressing bug fixes, performance improvements, and feature enhancements. The codebase receives consistent attention to code quality and stability. Community engagement remains strong, with users contributing rules, reporting issues, and providing feedback that shapes the tool's direction. The maintainers prioritize backward compatibility while incrementally expanding the engine's capabilities to handle new detection challenges.