Change custom behavioral, YARA scanner and memory dump rule files

Prev Next

You can add or modify the files for custom behavioral, YARA scanner and memory dump rules.

  1. Log on to the Intelligent Sandbox web interface.

  2. Select ManageImage & Software Content Update.

  3. Select the YARA Rules tab.

  4. To download the file from the Intelligent Sandbox database onto your client, click the File Name link.

  5. Open the file that you downloaded in a text editor, make your changes, then save the file.

  6. On the Content Update page, click Browse, locate and open the file, then click Upload.

  7. Select the required option from the following:

    • Custom Behavioral Rule

    • Custom YARA Scanner

    • Custom Memory Dump Rules

  8. Click OK.