You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi guys
I have all rules and yara rules enabled and the rule YARA.davivienda can be problematic in business environments. There is a real bank called Davivienda, and everytime someone sends a mail with this name, mail is not delivered and says that is a virus
There is any way to disable a yara rule? I tried with "-w" option and putting YARA.davivienda, but nothing
The rule is in file bank_rule.yar
Thanks!
The text was updated successfully, but these errors were encountered:
If you edit the yar file itself it will get autoupdated back again so I would suggest either reporting the issue to the original repo here https://github.com/Yara-Rules/rules or disabling the bank_rule.yar.
The disabling of the bank_rule.yar is very simple to do in the master.config by changing the line email/bank_rule.yar|MEDIUM to email/bank_rule.yar|DISABLED. I don't think you can disable a specific yar file from the user.conf?
Maybe there is another way? @extremeshok could correct me :)
Hi guys
I have all rules and yara rules enabled and the rule YARA.davivienda can be problematic in business environments. There is a real bank called Davivienda, and everytime someone sends a mail with this name, mail is not delivered and says that is a virus
There is any way to disable a yara rule? I tried with "-w" option and putting YARA.davivienda, but nothing
The rule is in file bank_rule.yar
Thanks!
The text was updated successfully, but these errors were encountered: