1
vote
Run/rerun yara rules from AXIOM Examine
Currently, users of AXIOM can ingest yara rules during case creation with AXIOM Process. However, in live cyber incidents an examiner may not always have the best yara rules available during initial processing, or additional intelligence may come to life about other potential malware strains etc. It would be extremely beneficial to allow examiners to ingest additional yara rules into existing AXIOM cases and rerun these against specific evidence items, similar to how additional keywords can currently be defined. It would also be useful if sigma rules could be added to existing cases, although yara would be more beneficial. Thanks!

*come to light, even!