Import custom behavioral, YARA scanner and memory dump rules

Prev Next

You can import custom YARA rule files such as custom behavioral, YARA scanner and memory dump rules into Intelligent Sandbox. You can import a maximum of two YARA rules versions. The second version that you upload becomes the Current file, and renders the first version the Backup files. Intelligent Sandbox applies the rules in the Current DAT file for malware detection.

  1. Log on to the Intelligent Sandbox web interface.

  2. Select ManageImage & Software Content Update.

  3. Select the YARA Rules tab.

  4. Click Browse, locate and open the file, then click Upload.

  5. Select the required option from the following:

    • Custom Behavioral Rule

    • Custom YARA Scanner

    • Custom Memory Dump Rules

  6. Click OK.

    If there are syntax errors in the file, Intelligent Sandbox displays the Uploaded file contains invalid Custom Behavioral Rules. Please check system log for more details. message.

    If you delete the Current YARA rule file, the Backup file replaces the Current file. To reinstate the Current file, click Revert.

Load-balancing scenario

Manually upload the Custom Yara Scanner files on these nodes:

  • Primary

  • Secondary

  • Backup

On the primary node, click PolicyAnalyzer Profile, select the analyzer profile, then click Edit. Enable Custom Yara Scanner.