
Adding New Rules
Click the “New Rule” button on the top to draft a new Yara rule and click “Create”. The rule name will be extracted from the definition:

Adding New Default Rules
If you want to change the default set of rules without having to add rules on each deployment, add a new yara file to./libs/file_enrichment_modules/yara_rules/dev/ for development or ./libs/file_enrichment_modules/yara_rules/prod/ for production.
Editing Existing Rules
To edit an existing rule, click the “Edit Rule” button under actions, modify the rule as wanted, and click “Save”:
Rule Alerts
Alerts for any matching rules will be shows in the Findings tab. This will include the data match as well as the rule details: