05-31-2020 10:47 PM
How i can deploy YARA rules by firepower
Solved! Go to Solution.
06-01-2020 02:52 AM
Please repost this question to Network Security thread.
(https://community.cisco.com/t5/network-security/bd-p/discussions-network-security)
Firepower uses AMP engine so if AMP itself supports Yara signature, maybe Firepower can have the same function. As far as I research AMP function, it has no function to implement Yara. AMP uses SHA-256, MD5 hash and ClamAV signature to detect malware. We can't convert from Yara to ClamAV signature(https://www.clamav.net/documents/using-yara-rules-in-clamav). So I think it's a quite low probability to have it in AMP and Firepower but not sure. So please post your question to Network Security thread.
06-01-2020 02:52 AM
Please repost this question to Network Security thread.
(https://community.cisco.com/t5/network-security/bd-p/discussions-network-security)
Firepower uses AMP engine so if AMP itself supports Yara signature, maybe Firepower can have the same function. As far as I research AMP function, it has no function to implement Yara. AMP uses SHA-256, MD5 hash and ClamAV signature to detect malware. We can't convert from Yara to ClamAV signature(https://www.clamav.net/documents/using-yara-rules-in-clamav). So I think it's a quite low probability to have it in AMP and Firepower but not sure. So please post your question to Network Security thread.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide