Kaspersky Anti Targeted Attack (KATA) Platform

Importing YARA rules

8 November 2023

ID 247719

To import YARA rules:

  1. In the window of the program web interface, select the Custom rules section, YARA subsection.
  2. Click Upload.

    This opens the file selection window.

  3. Select the YARA rules file that you want to upload and click the Open button.

    This closes the file selection window and opens the Import YARA rules window.

    The maximum allowed size of an uploaded file is 20 MB.

    A report is displayed in the lower part of the window. The report contains the following information:

    • The number of rules that can be successfully imported.
    • The number of rules that will not be imported (if any).

      For each rule that cannot be imported, its name is listed.

  4. Select the Traffic scan check box if you want to use imported rules for streaming scans of objects and data received at the Central Node.
  5. If necessary, enter any additional information in the Description field.

    The Importance field cannot be edited. By default, alerts generated by uploaded YARA rules are assigned a high level of importance.

  6. Under Apply to, select check boxes corresponding to servers on which you want to apply the rules.

    This field is displayed only when you are using the distributed solution and multitenancy mode.

  7. Click Save.

Imported rules are displayed in the table of YARA rules.

See also

Managing user-defined YARA rules

Viewing the YARA rule table

Configuring YARA rule table display

Viewing YARA rule details

Filtering and searching YARA rules

Clearing a YARA rule filter

Enabling and disabling YARA rules

Deleting YARA rules

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.