Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control: How to Rebuild Yara.bt9

App Control: How to Rebuild Yara.bt9

Environment

  • App Control Server: All Supported Versions
  • Windows Server: All Supported Versions

Objective

Rebuild the Yara.bt9 file downloaded by Agents from the App Control Server.

Resolution

  1. Login to the application server as the Carbon Black Service Account.
  2. Browse to: "C:\Program Files (x86)\Bit9\Parity Server\configxml"
  3. Move all Yara*.bt9 files to a backup location outside of the Bit9 directory, such as the desktop.
  4. Browse to: "C:\Program Files (x86)\Bit9\Parity Server\hostpkg"
  5. Move the Yara.bt9 file to the backup location.
  6. Restart the service: App Control Server.
  7. Verify the Yara files were recreated in the "configxml" and "hostpkg" directories.

Additional Notes

  • The new Yara.bt9 file will have a new hash, and all Agents will be instructed to download the updated Yara file.
  • If the Resource Download Location has been altered the new Yara.bt9 file will need to be copied to this location.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-16-2022
Views:
245
Contributors