Skip to content

Importing additional YARA rules to Strelka #13421

Locked Answered by defensivedepth
f4ncyz4nz4 asked this question in Q&A
Discussion options

You must be logged in to vote

You can add custom git repos, as described by our docs: https://docs.securityonion.net/en/2.4/yara.html#custom-yara-repositories

Once you have added them, Synchronize the Grid, give it about 15 min, then run manually run a Strelka Full Update in the Detections interface.

Replies: 5 comments 5 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Comment options

You must be logged in to vote
1 reply
@defensivedepth
Comment options

Comment options

You must be logged in to vote
1 reply
@defensivedepth
Comment options

Comment options

You must be logged in to vote
3 replies
@defensivedepth
Comment options

@f4ncyz4nz4
Comment options

@defensivedepth
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants