IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Response: Does the Yara Connector Require File Types to Be Specified in Rules?

CB Response: Does the Yara Connector Require File Types to Be Specified in Rules?

Environment

  • CB Response Server: All Supported Versions
  • CB Response Yara Connector: All Supported Versions

Question

  • Are file type specifications required for Yara Connector rules?

Answer

  • No, since Yara rules are based on strings, a file extension specification is not required. 

Additional Notes

  • Regular expressions can also be used in Yara Rules.
  • Functionally, the Yara connector scans the modulestore, which collects PE / executable files. 
    • The majority of file extensions will consist of: .exes , .dlls and .sys files.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
432
Contributors