elastic / elastic/docs-content

[Internal]: Custom YARA signatures as Endpoint artifact

Open
#7,080 3 comments 1 reaction 1 assignee Claimed by @natasha-moore-elastic View on GitHub
Team:Experience
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Description

We're introducing a new feature called 'Custom YARA signatures'. It'll be an Endpoint artifact (next to Trusted applications, Endpoint exceptions etc.), and it allows users to create/import/manage YARA rules and assign them globally or per-policy in a similar fashion as other Endpoint artifacts.

### Additional notes/todos
- add Custom YARA signatures to 'unavailable features on downgrade' [list](https://www.elastic.co/docs/deploy-manage/deploy/elastic-cloud/project-settings#project-features-add-ons), similarly to https://github.com/elastic/docs-content/issues/6817
- When documenting supported YARA modules, let's keep out `tests`. See https://github.com/elastic/kibana/pull/282561#issuecomment-5326775325

### Resources

Epic: https://github.com/elastic/security-team/issues/13807
Design: https://www.figma.com/design/NWxuevM1wyjK8DGkWegLX5/-9.5--YARA-Rules?node-id=1-87532&p=f&t=qwj43EQjUc5QSORR-0

Work is still in progress.

### Which deployment methods does this change impact?

Elastic On-Prem and Cloud (all)

### Feature differences

It'll be the same in all environments.

### What Elastic Stack release is this request related to?

9.6

### Serverless release

Synced with 9.6 ESS release as it's tied to Elastic Agent versioned release

### Collaboration model

The documentation team will create the first draft

### Point of contact.

**Main contact:** @gergoabraham

**Stakeholders:** @raqueltabuyo @dasansol92

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.