Access official resources from Carbon Black experts
/etc/cb/integrations/cb-yara-connector/yara_rules/
Yara Manager > Yara Rules > Choose File > Upload Rule
yara <yar file name> <directory> Example: yara /tmp/sample.yar .2. No output indicates the rule compiled without error. Any errors encountered may note the line number and error encountered. Example errors:
error: rule "sample" in /tmp/sample.yar(3): non-ascii character error: rule "sample" in /tmp/sample.yar(3): syntax error, unexpected end of file3. Yara syntax errors may also appear in the Yara Connector logs.
less /var/log/cb/integrations/cb-yara-connector/yaraconnector.log4. To verify the compiled Yara rules are actually tagging binaries, run this search query in the Process Search page:
alliance_score_yara:*
Copyright © 2005-2023 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.