plyara
Parse YARA rules
Decision gist · record as of 2026-08-14
Yes, if you work with YARA rules and need to parse or transform them programmatically. The package is stable, has no dependencies, and installs easily. Maintenance is dormant but not abandoned—the repository is still active. Be aware that the last release was over a year ago, so if you need recent bug fixes or features, check the repository's open issues first.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Low friction install with no runtime dependencies.
- Maintenance is dormant—last release was 554 days ago—but the repository remains active with recent commits and the package is marked Production/Stable.
License · maintenance · safety
permissive license (permissive) — Licensed under Apache (permissive), meaning you can use, modify, and distribute plyara freely in commercial and private projects with minimal restrictions.
last release 2025-02-06 (554 days) · last repo commit 2025-02-06 · 195 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 135,207 downloads/mo, #11,449 on PyPI
Alternatives
Verify before relying
pip install plyara
import plyara
parser = plyara.Plyara()
rules = parser.parse_string('rule MyRule { strings: $a="1" condition: false }')
print(rules[0]['rule_name'])- Whether the parser handles all YARA syntax variants or only a subset of the YARA specification.
- Performance characteristics when parsing very large rule files or rule sets.
What it is and what it does
Plyara is a lexer and parser that converts YARA rule files into structured Python dictionaries, making it possible to programmatically inspect, transform, and analyze malware detection rules. It exposes both a library API for use in Python applications and a command-line tool for batch processing rule files into JSON. The package has no external runtime dependencies and requires only Python 3.10 or later.
Typical use cases include extracting indicators from rule sets, updating rule metadata in bulk, linting or validating rule syntax, analyzing rule dependencies, and building tooling around YARA rule management. The parser preserves both the parsed structure (rule name, strings, conditions, metadata) and the raw text of each section, allowing users to work with either representation depending on their needs.
Use it for
- Extract indicators (file hashes, IP addresses, domains) from a corpus of YARA rules for threat intelligence.
- Validate and lint YARA rules in bulk to catch syntax errors or policy violations before deployment.
- Analyze rule dependencies and imports to understand which rules depend on external modules.
- Transform rule metadata across large rule sets (e.g., update threat levels or add tags programmatically).
- Build custom rule analysis tools that operate on parsed rule dictionaries rather than raw text.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you work with YARA rules and need to parse or transform them programmatically.
The package is stable, has no dependencies, and installs easily. Maintenance is dormant but not abandoned—the repository is still active. Be aware that the last release was over a year ago, so if you need recent bug fixes or features, check the repository's open issues first.
Install
plyara on PyPI
Before you install
Low friction install with no runtime dependencies. Maintenance is dormant—last release was 554 days ago—but the repository remains active with recent commits and the package is marked Production/Stable.
Requires Python 3.10 or later.
License in practice
Licensed under Apache (permissive), meaning you can use, modify, and distribute plyara freely in commercial and private projects with minimal restrictions.
Quickstart
pip install plyara
import plyara
parser = plyara.Plyara()
rules = parser.parse_string('rule MyRule { strings: $a="1" condition: false }')
print(rules[0]['rule_name'])
Verify before relying
- Whether the parser handles all YARA syntax variants or only a subset of the YARA specification.
- Performance characteristics when parsing very large rule files or rule sets.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Dormant 554 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 135,207 / month, #11,449 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: SecurityTopic :: Utilities |
Evidence: plyara-2.2.8-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “yara rule parser”
- plyaraParses YARA rule files into Python dictionary representations,…
- yara-pythonyara-python provides a Python interface to YARA, enabling you to…
- cisco-ai-mcp-scannerScans MCP (Model Context Protocol) servers and tools for security…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also yara-python · yara-x · dockerfile-parse · skope-rules · cisco-ai-mcp-scanner · pygmars · json-logic · pylama · panzi-json-logic · rply