Hello,
Intelligence hunting syntax is richer than the plain Yara syntax because it defines several externals. The ones that might particularly interesting for you are:
- file_type
- tags
- positives
This enables you to write a simple rule such as:
rule Example_1
{
condition:
tags contains "apk" and positives > 10
}
This would trigger on any APK sample with more than 10 AV detections. Similarly, you can combine these new features with the traditional Yara syntax, in order to focus exclusively on APKs that contain certain patterns, etc.
You can learn more about this at:
Regards.