YARA

Turkish equivalent: YARA eşleştirme kuralıDomain: Cybersecurity

A rule language and matching engine used to describe byte, string and structural indicators for classifying or hunting files and memory artifacts.

Rule Structure

A YARA rule can combine text, hexadecimal patterns and regular expressions with Boolean conditions. Rules are useful for expressing families of observable indicators rather than relying only on one file hash.

Quality Boundary

A matching rule is not proof of malicious intent. Generic strings or weak conditions can produce false positives, while obfuscation or version change can create false negatives.

Rules should therefore be tested against representative positive and negative corpora.

Forensic Use

YARA can be applied to files, memory dumps and extracted artifacts. Match offsets and the exact rule/version should be preserved when the result becomes part of an investigation.