Yara Rules for SIEM Detections in Wazuh

98 views
Skip to first unread message

Grayden Odum

unread,
Aug 26, 2023, 9:42:09 PM8/26/23
to Wazuh | Mailing List
I am hoping to use Yara rules for detections in the SIEM. I understand there is documentation for deploying Yara rules to endpoints.

However, I am hoping to have the ability to use Yara rules in Wazuh the same way the XML rules are used.

Is this possible? And if so, how can this be deployed/enabled on the Wazuh Manager?

Thanks in advance.

Olusegun Adenrele Oyebo

unread,
Aug 27, 2023, 9:41:26 AM8/27/23
to Wazuh | Mailing List

Hello Grayden,

Thank you for using Wazuh.

At the moment Wazuh's primary focus is on endpoint security hence it's not directly designed to integrate yara rules on the Wazuh server the same way you would integrate on an endpoint. At the same time this is actually a good use-case we can look into internally and when we have an update on how this can be achieved, you will be duly informed on our various channels. For now I'll leave you with some links below on integrations with yara:

I hope this was able to provide clarity. Do not hesitate to get back to us in case you have any other query.

Best Regards.

Reply all
Reply to author
Forward
0 new messages