YARA support, in detail.

Documented work with YARA rules or matching. Check the profile for scanning, rule handling and component requirements.

Filter these tools

Check the actual function

Each entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.

Before you connect it

Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.

13 tools with documented YARA support.

DFIR ORC

Digital forensics · France

Read the tool profile

Documented support

Uses configured YARA rules for file matching. In the documented 10.3.x scanner, blocks currently falls back to file-mapping behavior for compatibility; legacy block scanning can miss whole-file matches. Timeouts and scan-method limits apply.

Dissect

Digital forensics · Netherlands

Read the tool profile

Documented support

The yara plugin scans files inside a forensic target using local rule files. Files above the configured maximum size are skipped; rule checking and decompression are configurable.

Tenzir

Feed automation · Germany

Read the tool profile

Documented support

Its yara operator runs YARA-X rules over finite byte input. It compiles source rules, does not accept precompiled rules, and documents module and input-size limits.

A missing tool may support this feature without having been checked in this research pass.

Send a source or correction