-
Notifications
You must be signed in to change notification settings - Fork 839
Deploy YARA rules remotely and privately #14899
Copy link
Copy link
Closed
Labels
#g-orchestrationOrchestration product groupOrchestration product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.customer-domoncustomer-seidelstoryA user story defining an entire featureA user story defining an entire feature~csaIssue was created by or deemed important by the Customer Solutions Architect.Issue was created by or deemed important by the Customer Solutions Architect.
Milestone
Metadata
Metadata
Assignees
Labels
#g-orchestrationOrchestration product groupOrchestration product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.customer-domoncustomer-seidelstoryA user story defining an entire featureA user story defining an entire feature~csaIssue was created by or deemed important by the Customer Solutions Architect.Issue was created by or deemed important by the Customer Solutions Architect.
Context
Why doesn't current YARA rule deployment with osquery work?
Changes
Product
yara_sigurl_authenticateflag enabled, osquery will send the node key when retrieving YARA rules, which will allow the Fleet server to authenticate the request before responding.Engineering
QA
Risk assessment
Manual testing steps
Testing notes
Confirmation