Yara

WHAT IS YARA?

Single API

Yara is a tool that helps malware researchers identify and classify malware samples. With Yara, you can create descriptions of malware families based on textual or binary patterns.

INTEGRATION ACTIONS:

Allows Yara scanning on file content.

WHOM IS IT BUILT FOR?

Internal IR Teams & Consultants

WHY IS IT USEFUL?

The Cyber Triage/Yara integration allows users to use the latest rules that antivirus software may not know to use. The integration gives consultants broader coverage when hunting in an enterprise and allows companies to scan for the latest threats. Consultants can also utilize the integration to customize what Cyber Triage is looking for and make it fit a specific use case.

WHERE IS IT USED?

Users can supply Yara rules in Cyber Triage to analyze collected files. Yara allows malware researchers to define binary patterns that can be easily shared. When you configure Cyber Triage with Yara rules, they will be applied to all collected files, such as startup items and scheduled tasks.

WHAT IS THE REQUIRED CYBER TRIAGE VERSION?

Standard and Team

ADDITIONAL LINKS:

https://virustotal.github.io/yara/

https://www.cybertriage.com/2018/search-for-advanced-malware-in-cyber-triage-using-yara-rules/ 

 https://github.com/Yara-Rules/rules  

*For more information about this integration contact our sales team:  Sales@cybertriage.com.

Visit site