Access official resources from Carbon Black experts
cd /etc/yum.repos.d curl -O https://opensource.carbonblack.com/release/x86_64/CbOpenSource.repo2. Install the cb-yara-manager
yum install python-cb-yara-manager
cd /etc/cb/integrations/cb-yara-manager cp config.py.example config.py2. Create the authentication file.
vi /etc/cb/integrations/cb-yara-manager/auth.conf [auth] api_token=< create a unique adequately_long_and_complex_password >(where adequately_long_and_complex_password_or_token is any passphrase.)
YaraManagerEnabled=true YaraManagerToken=< insert the unique adequately_long_and_complex_password >4. To invoke the new cb.conf changes run
/usr/share/cb/cbservice cb-coreservices restart5. Start the service.
systemctl start cb-yara-manager6. Confirm that it is running.
ps -ef | grep -i manager (there should be 2 instances running)7. View Yara Manager in the browser after authenticating to the EDR server.
https://<EDR server IP>/connector/yara
Copyright © 2005-2023 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.