Sign inSign up

strubie/yara

By strubie

•Updated over 5 years ago

Proof of Concept - Prebuilt container to allow automated binary analysis from CarbonBlack Cloud EEDR

Image
1

4.3K

strubie/yara repository overview

Proof of Concept - Prebuilt docker container to allow automated binary analysis from Carbonblack PSC EEDR, BInary Tool-kit and Yara.

PreReq's:

  • VMware Carbon Black Cloud EEDR with Binary Collection turned on *Feed Id Created in Carbon Black EEDR
  • API Token that has access to UBS to pull binaries, Interact with Threat Feeds and Run Process Search.
  • User Guide for Binary tool-kit walk through the setup of all of this: https://github.com/carbonblack/cbc-binary-toolkit/wiki/User-Guide⁠

Steps To use:

  1. Pull Container: docker pull strubie/yara
  2. Run Container: docker run -it strubie/yara
  3. edit /etc/carbonblack/credentials.psc adding your URL and API token that has process search priviledges
  4. edit /root/binary-toolkit/binary.yaml adding URL, API Token( Threat Feed and UBS), org_key, and AND feed_id.
  5. View the contents of /root/binary-toolkit/rules.yara - There is a sample rule provided but please add your own.
  6. View the contents of /root/yara.sh - This script once executed will run the process query you see in the script every 15 minutes and send those resulting binaries to the yara engine. Adjust this query and timing to meet your needs.
  7. When all configs and script have been reviewed you can execute /root/yara.sh

Tag summary

Content type

Image

Digest

Size

542.5 MB

Last updated

over 5 years ago

docker pull strubie/yara