The custom memory dump rules are a set of YARA rules. You can create a custom memory dump rule in Intelligent Sandbox to detect a specific behavior by utilizing the user memory dump log of a sample.
Additionally, you can also create custom memory dump rules to detect zero-day or near-zero-day malware. You can either create your own custom memory dump rules or use YARA rules from a third party.
To use the custom memory dump rule, you must: