yara-x
Python bindings for YARA-X
Decision gist · record as of 2026-08-14
Yes. yara-x is actively maintained, has no security vulnerabilities, permissive licensing, and pre-built wheels that minimize install friction. Install it if you need rule-based pattern matching for malware detection, forensics, or threat hunting. The zero runtime dependencies and straightforward API make it low-risk to add to security tooling.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; compiled Rust extension may require a compatible C runtime on some systems.
- Medium install friction due to compiled Rust bindings, but wheels are pre-built for common platforms (CPython ABI3, PyPy, Linux/macOS/Windows).
- Active maintenance with recent releases.
License · maintenance · safety
permissive license (permissive) — Permissive license (BSD) allows commercial and private use without significant restrictions.
last release 2026-06-24 (51 days) · last repo commit 2026-08-11 · 1,249 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 447,011 downloads/mo, #6,609 on PyPI
Alternatives
Verify before relying
import yara_x
rules = yara_x.compile('''
rule test {
strings:
$a = "foobar"
condition:
$a
}''')
results = rules.scan(b"foobar")
print(results.matching_rules[0].identifier)- Performance characteristics (scan speed, memory usage) on large binaries or rule sets.
- Compatibility with custom YARA rule syntax extensions or YARA 4.x rule features.
- Whether the library supports streaming/incremental scanning or only in-memory buffers.
What it is and what it does
yara-x is the official Python interface to YARA-X, VirusTotal's pattern-matching engine designed for cybersecurity and forensic use. It lets you compile YARA rules (text-based pattern definitions) and scan binary data to find matches. The library wraps a Rust implementation, providing both speed and memory safety while keeping the Python API simple: compile rules once, then call scan() on binary buffers to get structured results showing which rules matched, which patterns within those rules fired, and at what offsets.
The package targets Python 3.9+ and comes with pre-built wheels for CPython and PyPy on Linux, macOS, and Windows, reducing installation friction. It has no runtime dependencies beyond the Python standard library, making it lightweight to add to existing projects. Active maintenance and permissive licensing make it suitable for both open-source and commercial security tooling.
Use it for
- Scan files or network traffic for known malware signatures using compiled YARA rules.
- Build forensic analysis pipelines that identify suspicious patterns in disk images or memory dumps.
- Integrate pattern matching into security monitoring or threat-hunting workflows.
- Detect indicators of compromise by matching rule sets against collected artifacts.
- Develop custom malware classification or triage systems based on rule-driven pattern detection.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
yara-x is actively maintained, has no security vulnerabilities, permissive licensing, and pre-built wheels that minimize install friction. Install it if you need rule-based pattern matching for malware detection, forensics, or threat hunting. The zero runtime dependencies and straightforward API make it low-risk to add to security tooling.
Install
yara-x on PyPI
Before you install
Medium install friction due to compiled Rust bindings, but wheels are pre-built for common platforms (CPython ABI3, PyPy, Linux/macOS/Windows). Active maintenance with recent releases.
Requires Python 3.9 or later; compiled Rust extension may require a compatible C runtime on some systems.
License in practice
Permissive license (BSD) allows commercial and private use without significant restrictions.
Quickstart
import yara_x
rules = yara_x.compile('''
rule test {
strings:
$a = "foobar"
condition:
$a
}''')
results = rules.scan(b"foobar")
print(results.matching_rules[0].identifier)
Verify before relying
- Performance characteristics (scan speed, memory usage) on large binaries or rule sets.
- Compatibility with custom YARA rule syntax extensions or YARA 4.x rule features.
- Whether the library supports streaming/incremental scanning or only in-memory buffers.
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 51 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 447,011 / month, #6,609 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: BSD LicenseProgramming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyProgramming Language :: Rust |
Evidence: yara_x-1.19.0-cp38-abi3-macosx_14_0_arm64.whl; yara_x-1.19.0-cp38-abi3-macosx_14_0_x86_64.whl; yara_x-1.19.0-cp38-abi3-manylinux_2_28_aarch64.whl; yara_x-1.19.0-cp38-abi3-manylinux_2_28_x86_64.whl; yara_x-1.19.0-cp38-abi3-win_amd64.whl; yara_x-1.19.0-pp311-pypy311_pp73-macosx_14_0_arm64.whl; yara_x-1.19.0-pp311-pypy311_pp73-macosx_14_0_x86_64.whl; yara_x-1.19.0-pp311-pypy311_pp73-manylinux_2_28_aarch64.whl; yara_x-1.19.0-pp311-pypy311_pp73-manylinux_2_28_x86_64.whl; yara_x-1.19.0-pp311-pypy311_pp73-win_amd64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “binary scanning rules”
- yara-xPython bindings for YARA-X, a pattern-matching engine for malware…
- cisco-ai-skill-scannerScans AI Agent Skills for prompt injection, data exfiltration, and…
- cisco-ai-mcp-scannerScans MCP (Model Context Protocol) servers and tools for security…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also plyara · yara-python · cisco-ai-mcp-scanner · maec · cisco-ai-skill-scanner · PyMeta3 · maco-extractor · guarddog · mail-parser · gitignorant