YARA rules are often made specifically for a certain variant of a threat using strings from a binary. What happens when the strings simply disappear or become obfuscated? This presentation will highlight key components to building YARA rules for finding newer variants or new versions of malware from the same threat actor, that will last through generations of the malware evolution process.