Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Yara no longer processing rules after cortex 2.0 update #245

Closed
Hestat opened this issue May 12, 2018 · 4 comments
Closed

Yara no longer processing rules after cortex 2.0 update #245

Hestat opened this issue May 12, 2018 · 4 comments
Assignees
Labels
category:bug Issue is related to a bug scope:cortex
Milestone

Comments

@Hestat
Copy link

Hestat commented May 12, 2018

Request Type

(select Bug, Analyzer or Feature and remove this line)
Bug

Work Environment

Question Answer
OS version (server) Ubuntu 16.04
OS version (client) Kali
Cortex Analyzer Name Yara
Cortex Analyzer Version 2.0
Cortex Version 2.0
Browser type & version I

Description

After updating from cortex v 1.1 to 2.0 yara no longer give back hits, I can run the yara analyzer for things that previously returned positive hits and it no longer triggers a detection

Complementary information

can't find anything useful in the logs and no error messages are returned. Perhaps my rule path is somehow not being processed?

@gertz27
Copy link

gertz27 commented May 24, 2018

I ran into the same issue and the only workaround I found was to hard code the rule path into the Python file for the Yara analyzer yara_analyzer.py.

@3c7 3c7 self-assigned this May 24, 2018
@3c7 3c7 added category:bug Issue is related to a bug scope:cortex labels May 24, 2018
@3c7
Copy link
Contributor

3c7 commented May 24, 2018

Just to make sure: you've updated the analyzer config accordingly in the cortex ui? Just took a look at the code and cannot find a mistake on the first glance.

@Hestat
Copy link
Author

Hestat commented May 27, 2018

I have updated them in the UI in several different manners, and none seem to work EX:

"/usr/local/src/rules/Webshells_index.yar","/usr/local/src/lw-yara/lw-rules_index.yar","/usr/local/src/rules/malware_index.yar", "/usr/local/src/rules/Exploit-Kits_index.yar"

and just

/usr/local/src/rules/Webshells_index.yar

to see if one works.

@3c7
Copy link
Contributor

3c7 commented May 28, 2018

Confirmed, fix will be merged with Hotfix 1.9.7.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:bug Issue is related to a bug scope:cortex
Projects
None yet
Development

No branches or pull requests

3 participants