Yara rules

The Yara rules page lets you manage the Yara rules for Threat Intelligence.

Figure 1. Yara rules page

Yara rules page

YARA rules are executed on every file transferred over network protocols such as hypertext transfer protocol (HTTP) or server message block (SMB). When a match is found, an alert of type SIGN:MALWARE-DETECTED is raised.

Live / refresh

The Live icon lets you change live view on, or off. When live mode is on, the page will refresh approximately every five seconds.

Add

This lets you add a new Yara rule.