Kaspersky Anti Targeted Attack (KATA) Platform

Managing user-defined YARA rules

8 November 2023

ID 247430

You can use YARA rules as YARA module databases to scan files and objects received at the Central Node and to scan hosts with the Endpoint Agent component.

In distributed solution and multitenancy mode, custom YARA rules can have one of the following types:

  • Global—Created on the PCN server. These rules are used to scan files and objects received at the PCN server and all SCN servers connected to that PCN server. Scanned files and objects belong to the tenant which the user is managing in the application web interface.
  • Local—Created on the SCN server. These rules are used to scan files and objects received at the SCN server. Scanned files and objects belong to the tenant which the user is managing in the application web interface.

When managing the application web interface, users with the Senior security officer role can import a YARA rule file into Kaspersky Anti Targeted Attack Platform using the application web interface.

Users with the Security auditor and Security officer roles can only view YARA rules.

In this section

Viewing the YARA rule table

Configuring YARA rule table display

Importing YARA rules

Viewing YARA rule details

Filtering and searching YARA rules

Clearing a YARA rule filter

Enabling and disabling YARA rules

Deleting YARA rules

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.