Run/rerun yara rules from AXIOM Examine

Back to Idea Board

1 vote

Run/rerun yara rules from AXIOM Examine

Currently, users of AXIOM can ingest yara rules during case creation with AXIOM Process. However, in live cyber incidents an examiner may not always have the best yara rules available during initial processing, or additional intelligence may come to life about other potential malware strains etc. It would be extremely beneficial to allow examiners to ingest additional yara rules into existing AXIOM cases and rerun these against specific evidence items, similar to how additional keywords can currently be defined. It would also be useful if sigma rules could be added to existing cases, although yara would be more beneficial. Thanks!

Idea Category: Magnet AXIOM oliver-ank shared this idea

One thought on “Run/rerun yara rules from AXIOM Examine

Comments are closed.