IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Performance Impact After Creating Custom Write Rule with Yara Tags

App Control: Performance Impact After Creating Custom Write Rule with Yara Tags

Environment

  • App Control Console: 8.9.0 and Higher
  • App Control Agent: 8.8.0 and Higher

Symptoms

Performance impact after creating a Custom Rule that includes Write Operations with Yara Tags.

Cause

The performance issue is caused because the Agent will be forced to analyze every write operation for the Yara Tag(s) specified.

Resolution

Avoid the use of a Custom Rule, and instead create a Yara Rule (Rules > Software Rules > Yara) that returns the correct predefined Yara Rule Tag.


Additional Notes

  • Examples of Custom Rules with Write Operations: File Creation Control, Advanced with Write Operation, Expert Rule with Write Operation, etc
  • YARA Rules are powerful and can have far-reaching, unexpected consequences. It is always recommended to test Custom Rules in a limited fashion before deploying to all endpoints.

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎10-11-2023
Views:
200
Contributors