Use the commands in this procedure to enable or disable Trellix YARA rules on your Malware Analysis appliance. You cannot use the Web UI to configure YARA rules.
Prerequisites
An established connection between the Malware Analysis appliance and the Internet.
Administrator or Operator access to the Malware Analysis appliance.
To enable or disable Trellix YARA rules:
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable the Trellix YARA rules.
To enable the Trellix YARA rules:
hostname (config) # yara policy fe
To disable the Trellix YARA rules:
hostname (config) # yara policy disable
Verify your configuration.
hostname (config) # show static-analysis config ..... Yara Configuration Yara policy : fe .....
Save your changes.
hostname (config) # write memory Saving configuration file ... Done!