Uploading YARA rules using the Web UI

Prev Next

Use the Settings > YARA Rules page to manage your YARA rules. On this page you can search your local machine for custom YARA rules files and upload them to the appliance. Before you search, you can select a file type to which to apply the YARA rule or select common to apply it to all supported file types. Additionally, you can view your files and the associated content types in a custom YARA rules table.

All_YaraRulesUpload_scap.png

See YARA rules on for information about how YARA rules are used and how they relate to threat management.

Note

If you use a Central Management System platform to upload a YARA rules file to an Intelligent Virtual Execution - Server appliance running Release 7.8.0 or newer, the Central Management System platform uploads the YARA rules file to other managed Intelligent Virtual Execution - Server appliances in the same appliance group.

Prerequisites

  • An established connection between the Intelligent Virtual Execution - Server appliance and the Internet.

  • You are logged in to the Web UI as an Admin or Operator access.

To upload a YARA rules file:

  1. Go to the Settings > YARA Rules page.

  2. Click Upload YARA File.

  3. Click Choose a File, then select the local YARA rule file you want to upload.

  4. In the Content Type drop-down list, specify the content type you wish to apply the YARA rule against:

    • Base content—Applies the YARA rule only to the file or content itself.

    • Active content—Applies the YARA rule to any macros generated by the file or content.

    • Both (Base content and Active content)—Applies the YARA rule to both the file or content and any macro associated with the file or content.

  5. In the File Type drop-down list, select the file type to which you want to apply the YARA rule, or select common if the rule applies to all supported file types.

  6. Click Update to upload the YARA rule file.

    If an invalid rule file is uploaded, or the selected file type does not match the contents of the YARA file, the Download File and the Download Error Log buttons appear. Use these buttons to download the invalid file and the error log.

To delete a YARA rule file:

  1. Go to the Settings > YARA Rules page.

  2. In the custom YARA rules table, locate the rule you want to delete.

  3. Select the box in the Delete column.

  4. Click Delete File.