VirusTotal YARA Hunting - Rules API

YARA Hunting - Rules

Business capability
Threat Detection & Response Management BC-620.30

Operations 4

GET /yara_rules VirusTotal List Crowdsourced YARA Rules #
GET /yara_rules/{id} VirusTotal Get a Crowdsourced YARA Rule #
GET /yara_rules/{id}/relationships/{relationship} VirusTotal Get Objects Descriptors Related to a Crowdsourced YARA Rule #
GET /yara_rules/{id}/{relationship} VirusTotal Get Objects Related to a Crowdsourced YARA Rule #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/virustotal-yara-hunting-rules-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

virustotal-yara-hunting-rules-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: VirusTotal API v3 - YARA Hunting (Livehunt, Retrohunt, IoC…
  version: '3.0'
  description: Livehunt, Retrohunt, the IoC Stream, and crowdsourced YARA rules — VirusTotal's hunting and notification surface.
  contact:
    name: VirusTotal / Google Threat Intelligence
    url: https://docs.virustotal.com/reference/overview
  license:
    name: VirusTotal Terms of Service
    url: https://www.virustotal.com/gui/terms-of-service
  x-generated-from: https://storage.googleapis.com/gtidocresources/guides/GTI_API_v3_openapi_spec_10022025.json
  x-last-validated: '2026-05-29'
servers:
- url: https://www.virustotal.com/api/v3
  description: VirusTotal / GTI API v3 production.
security:
- VTApiKey: []
tags:
- name: YARA Hunting - Rules
  description: YARA Hunting - Rules
paths:
  /yara_rules:
    get:
      tags:
      - YARA Hunting - Rules
      deprecated: false
      description: 'This endpoint lists the different Google Threat Intelligence''s Crowdsourced YARA rules.


        ```json Example response

        {

        "meta": {

        "cursor": "Ck8KDwoCbG0SCQjdvIy9kdv-AhI4ahFzfnZpcnVzdG90YWxjbG91ZHIjCxIIWWFyYVJ1bGUiFTAwM2UxYzUxZWZ8UEtfQVhBX2Z1bgwYACAB"

        },

        "data": [

        {

        "attributes": {

        "name": "PK_AXA_fun",

        "tags": [

        "AXA"

        ],

        "matches": 0,

        "author": "Thomas Damonneville",

        "enabled": true,

        "rule": "rule PK_AXA_fun : AXA\n{\n meta:\n description = \"Phishing Kit impersonating AXA banque\"\n licence = \"GPL-3.0\"\n author = \"Thomas Damonneville\"\n reference = \"\"\n date = \"2023-05-02\"\n comment = \"Phishing Kit - AXA - using a fun.php page\"\n\n strings:\n // the zipfile working on\n $zip_file = { 50 4b 03 04 }\n $spec_dir = \"css\"\n $spec_dir2 = \"images\"\n // specific file found in PhishingKit\n $spec_file = \"detail.html\"\n $spec_file2 = \"fun.php\"\n $spec_file3 = \"fin.html\"\n $spec_file4 = \"axa_pp_blanc.min.css\"\n\n condition:\n // look for the ZIP header\n uint32(0) == 0x04034b50 and\n // make sure we have a local file header\n $zip_file and\n // check for file\n all of ($spec_file*) and\n all of ($spec_dir*)\n}",

        "creation_date": 1682985600,

        "meta": [

        {

        "key": "description",

        "value": "Phishing Kit impersonating AXA banque"

        },

        {

        "key": "licence",

        "value": "GPL-3.0"

        },

        {

        "key": "author",

        "value": "Thomas Damonneville"

        },

        {

        "key": "reference",

        "value": ""

        },

        {

        "key": "date",

        "value": "2023-05-02"

        },

        {

        "key": "comment",

        "value": "Phishing Kit - AXA - using a fun.php page"

        }

        ],

        "last_modification_date": 1683185194

        },

        "type": "yara_rule",

        "id": "003e1c51ef|PK_AXA_fun",

        "links": {

        "self": "https://www.virustotal.com/api/v3/yara_rules/003e1c51ef|PK_AXA_fun"

        }

        }

        ],

        "links": {

        "self": "https://www.virustotal.com/api/v3/yara_rules?limit=1",

        "next": "https://www.virustotal.com/api/v3/yara_rules?cursor=Ck8KDwoCbG0SCQjdvIy9kdv-AhI4ahFzfnZpcnVzdG90YWxjbG91ZHIjCxIIWWFyYVJ1bGUiFTAwM2UxYzUxZWZ8UEtfQVhBX2Z1bgwYACAB&limit=1"

        }

        }

        ```


        The `filter` parameter allows to filter the rules according to the values of certain attributes. For example you can get only the enabled rules with `enabled:true`. With `name:foo` and `foo` you can search for rules having the word "foo" in their names or in their meta values. Notice however that this only works with full words (words delimited by non-alphanumeric characters), if the rule''s name is "foobar" it won''t appear if you filter with `name:foo`. You can combine multiple filters separating them with spaces, for example: `filter=enabled:true name:foo`.


        All the accepted filters are: `author`, `creation_date`, `enabled`, `included_date`, `last_modification_date`, `name`, `tag`, `threat_category`.


        The `order` parameters control the order in which rulesets are returned, accepted orders are: `matches`, `creation_date`, `included_date` and `modification_date`. You can prepend `+` and `-` suffixes to specify ascending and descending orders (examples: `name-`, `creation_date+`, ). If not suffix is specified the order is ascending by default.'
      operationId: listCrowdsourcedYaraRules
      parameters:
      - description: Maximum number of rules to retrieve
        in: query
        name: limit
        schema:
          default: 10
          format: int32
          type: integer
      - description: Return the rules matching the given criteria only
        in: query
        name: filter
        schema:
          type: string
      - description: Sort order
        in: query
        name: order
        schema:
          type: string
      - description: Continuation cursor
        in: query
        name: cursor
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal List Crowdsourced YARA Rules
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /yara_rules/{id}:
    get:
      tags:
      - YARA Hunting - Rules
      deprecated: false
      description: Returns a YARA rule object.
      operationId: getACrowdsourcedYaraRule
      parameters:
      - description: Rule identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get a Crowdsourced YARA Rule
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /yara_rules/{id}/relationships/{relationship}:
    get:
      tags:
      - YARA Hunting - Rules
      deprecated: false
      description: Same as /yara_rules/{id}/{relationships} except it returns just the related object's descriptor (and context attributes, if any) instead of returning all attributes.
      operationId: crowdsourcedYaraRuleRelationshipDescriptorsEndpoint
      parameters:
      - description: Rule identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: Relationship name (see [table](ref:yara-rule-object#relationships))
        in: path
        name: relationship
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get Objects Descriptors Related to a Crowdsourced YARA Rule
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /yara_rules/{id}/{relationship}:
    get:
      tags:
      - YARA Hunting - Rules
      deprecated: false
      description: 'YARA rule objects have relationships to other objects. As mentioned in the Relationships section, those related objects can be retrieved by sending `GET` requests to the relationship URL.


        The relationships supported by YARA rule objects are documented in the YARA Rules API object page.'
      operationId: crowdsourcedYaraRuleRelationshipEndpoint
      parameters:
      - description: Rule identifier
        in: path
        name: id
        required: true
        schema:
          type: string
      - description: Relationship name (see [table](ref:yara-rule-object#relationships))
        in: path
        name: relationship
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get Objects Related to a Crowdsourced YARA Rule
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  securitySchemes:
    VTApiKey:
      type: apiKey
      in: header
      name: x-apikey
      description: Personal VirusTotal / GTI API key. Found in the user menu of your VirusTotal account.