Importing additional YARA rules to Strelka #13421
-
Hello,
|
Beta Was this translation helpful? Give feedback.
Replies: 5 comments 5 replies
-
following , interested in same |
Beta Was this translation helpful? Give feedback.
-
You can add custom git repos, as described by our docs: https://docs.securityonion.net/en/2.4/yara.html#custom-yara-repositories Once you have added them, |
Beta Was this translation helpful? Give feedback.
-
Thanks very much.
|
Beta Was this translation helpful? Give feedback.
-
Last question, where should I find those imported rules on the sensor? |
Beta Was this translation helpful? Give feedback.
-
I followed every step mentioned above, I also looked and followed the istructions of discussion #13405. The only way I found to do that is to copy the created repo also at But if I eliminate one of the 2 repos, again the Detection interface shows only the "securityonion-yara" rules. Please, can someone help me? |
Beta Was this translation helpful? Give feedback.
You can add custom git repos, as described by our docs: https://docs.securityonion.net/en/2.4/yara.html#custom-yara-repositories
Once you have added them,
Synchronize the Grid
, give it about 15 min, then run manually run a StrelkaFull Update
in the Detections interface.