I'm trying to run a Yara Scan to scan the filesystem for malicious files. I have a Yara Rule file that I'm trying to reference however I have not been able to figure out which Artifact supports referencing the Yara Rule File. The only artifact that I've seen that allows me to point to the .YAR file that I've uploaded to the public URL is the RemoteYara.Process scan.
--
You received this message because you are subscribed to the Google Groups "velociraptor-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an email to velociraptor-dis...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/velociraptor-discuss/fc2539b1-ef24-40d6-9788-34fbfba11244n%40googlegroups.com.
I should also specify that the YAR rules I’m using calls to import PE, HASH, MATCH and TIME. When using the ‘Windows.Search.Yara’ with this ruleset, I get the following error: Failed to initialize YARA compiler: Invalid field name “signatures”
Thanks,
Ryan
--
|
To view this discussion on the web visit https://groups.google.com/d/msgid/velociraptor-discuss/293066DD-9CDD-4974-94FF-0DE4DEA1FCCB%40hxcore.ol.