Managing YARA Rule Files Parent topic

Procedure

  1. Go to Virtual AnalyzerSandbox Management, and then go to the YARA Rule tab.
  2. To add a new YARA rule:
    1. Click Add.
      The Add YARA Rule File window appears.
    2. Specify the following:
      • Rule file: Browse and select a YARA rule file to add.
      • Files to analyze: Specify the file types that Virtual Analyzer associates with this YARA rule file.
    3. Click Add.
      Virtual Analyzer validates the YARA rule file before adding it. For details about creating valid YARA rule files, see Creating a YARA Rule File.
  3. To edit an existing YARA rule:
    1. Click the File name of the YARA rule file to be edited.
      The Edit YARA Rule File window appears.
    2. Specify the following:
      • Rule file: Browse and select another YARA rule file to replace the existing one.
      • Files to analyze: Specify the file types that Virtual Analyzer associates with this YARA rule file.
    3. Click Save.
  4. To download a copy of the YARA rule file, select one YARA rule file, and click Export.
  5. To delete a YARA rule file, select one or more YARA rules, and click Delete.