How to Manage YARA Rules

Click YARA rules at the top of the Dr.Web vxCube main page to see all YARA rules available for your account. The YARA rule list that opens includes the following information for each rule:

The rule type (rule_user for user rules and rule_system for system rules).

Name: The rule name.

Maliciousness: The maliciousness level specified in the rule.

Tags: Tags specified in the rule.

Matches: The total amount of matches for the particular rule.

Last matched: The date when the rule was last triggered. If the trigger occurred today, the time will be shown instead of the date.

State: The current state of the rule (enabled/disabled).

 

yara rules

Figure 9. The list of YARA rules

In the list of YARA rules, you can:

Search for rules by their names and tags

Filter rules by type (system/user)

Sort rules

View information about rule matches (the name of the file that the rule was triggered on, the date of triggering, OS)

Edit, delete, and enable/disable rules

To search for a rule

To find specific rule(s), type their name or tags (or a portion of them) in the search box located at the top right of the rule list.

To filter rules by type

Next to the header of the rule list, click arr_dropdown_yara and choose the filter option: YARA rules: All, YARA rules: System, or YARA rules: User.

To sort rules

Click the header of the column you want to sort by. At the left of the header arr_sort_up or arr_sort_down will appear. To change the sorting direction, click the header again.

To view information about the rule matches

In the Matches column, click the number of matches for the required rule. The page of reports on matches for this rule opens.

To edit a rule

Hover over the row of the rule and click pen on the right.

To delete a rule

Hover over the row of the rule and click bin on the right.

To disable or enable a rule

In the row of the rule, turn the toogle_on switcher on or off.

To set the number of rules displayed per page

At the bottom right, select the required value (10, 25, 50, or 100) from the drop-down.