YARA
- 10 Oct 2025
- 1 Minute to read
- Print
- Dark
This documentation version is deprecated, please click here for the latest version.
YARA
- Updated on 10 Oct 2025
- 1 Minute to read
- Print
- Dark
Article summary
Did you find this summary helpful?
Thank you for your feedback!
Note that instead of using the yara_update command directly it is recommended to use the YARA extension available through the web UI and REST interface.
yara_scan
Scan for a specific YARA signature in memory and files on the endpoint.
Platforms:
The memory component of the scan on MacOS may be less reliable due to recent limitations imposed by Apple.
yara_update
Update the compiled YARA signature bundle that is being used for constant memory and file scanning on the sensor.
Platforms:
Was this article helpful?