adding basic yara functionality by default #174
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Describe the change
Adds a rules.yara file to the backend, and mounts the file in the backend's /etc/yara directory to ensure there is at least one rule. Yara rules can be added without having to rebuild the container, just must restart before rescanning a file.
Describe testing procedures
I ran built strelka before and after changes to verify it works as intended.
Sample output
Changes the scan yara from "compiling error" to show the test rule result.
Checklist