Import File YARA
Verified
Threat Intelligence
Overview
This connector ingests YARA rules into OpenCTI, converting them into Indicators.
This connector ingests YARA rules into OpenCTI, converting them into Indicators. As YARA files can contain one or multiple YARA rules, the connector can operate in two modes:
- Single Indicator Mode: Combines all YARA rules contained in the .yar file into one STIX Indicator. (Split Rules option: False).
- Split Indicator Mode: Creates individual STIX Indicators for each YARA rule contained in the .yar file. (1 flag per YARA rule) (Split Rules option: True).