Skip to main content
Sticky

How to install a YARA rule with Veeam


Rick Vanover
Forum|alt.badge.img+10

We’ve updated the Script Library section to include YARA rules. I’ve made a quick video (sorry for the cheesy graphics...) on how to install a YARA rule from this site and perform your first scan!

 

12 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8485 comments
  • December 15, 2023

Thanks for sharing this, Rick.  I was about to ask if you were going to do a “how to” video for installing the rules.  😋


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4133 comments
  • December 15, 2023

Absolutely GREAT beginner ‘how-to’ vid on using these rules Rick. Thanks!


Rick Vanover
Forum|alt.badge.img+10
  • Author
  • RICKATRON
  • 766 comments
  • December 15, 2023
Chris.Childerhose wrote:

Thanks for sharing this, Rick.  I was about to ask if you were going to do a “how to” video for installing the rules.  😋

Hahaha that’s funny. But I think that screen that has the scan needs some explanation and people just need to use it.


Rick Vanover
Forum|alt.badge.img+10
  • Author
  • RICKATRON
  • 766 comments
  • December 15, 2023

Oh and I didn’t want everyone to wait during the video, but here is the result of the scan:
 

 


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4133 comments
  • December 15, 2023

Personally, I don’t like how the date is formatted after choosing the dates...can be confusing. And yeah...how you choose it is odd, but makes sense. I think the wording on those 2 dates could be changed to be more descriptive, like “Start from (today)” instead of Start Date; and “End Date (until)”, or something similar for the ‘End Date’.

Hopefully folks will read up on what each option is used for.


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4133 comments
  • December 15, 2023
Rick Vanover wrote:

Oh and I didn’t want everyone to wait during the video, but here is the result of the scan:
 

 

Cool! I forgot about even seeing the results! 😂😆


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8485 comments
  • December 15, 2023
Rick Vanover wrote:
Chris.Childerhose wrote:

Thanks for sharing this, Rick.  I was about to ask if you were going to do a “how to” video for installing the rules.  😋

Hahaha that’s funny. But I think that screen that has the scan needs some explanation and people just need to use it.

Yeah, going to take some getting used to for sure.  Going to play in the homelab with these sample rules.


Geoff Burke
Forum|alt.badge.img+22
  • Veeam Legend, Veeam Vanguard
  • 1317 comments
  • December 16, 2023

Excellent video and will really help everyone just starting out with Yara scans!

 


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8485 comments
  • December 16, 2023

Got them installed in the lab and testing.  Very interesting for sure.


Thanks for the video. Will there be an option later to run multiple YARA rules at the same time?


Rick Vanover
Forum|alt.badge.img+10
  • Author
  • RICKATRON
  • 766 comments
  • January 30, 2024
Mike Edwards wrote:

Thanks for the video. Will there be an option later to run multiple YARA rules at the same time?

Mike Edwards wrote:

Thanks for the video. Will there be an option later to run multiple YARA rules at the same time?

Hi Mike - it is not implemented currently (nor scan on multiple images). Both are feature requests on our side/internally.


Rick Vanover
Forum|alt.badge.img+10
  • Author
  • RICKATRON
  • 766 comments
  • January 30, 2024
Mike Edwards wrote:

Thanks for the video. Will there be an option later to run multiple YARA rules at the same time?

Oh and welcome to the Veeam Community @Mike Edwards - looks like your first comment here.