Skip to main content

Comparison with reference list and threat feed

  • October 21, 2024
  • 1 reply
  • 16 views

rahul7514
Forum|alt.badge.img+10

Hi All 

I am trying to write a YARA L query where in  from my logs (process hash values and file hash values) needs to be compared with 

1) Reference list IOC feed

2) GCTI safe browsing feed. 

Can i do this both in a single query

when trying i am getting this error "

  • semantic analysis: match variable sha256 is not assigned to an event field

 

1 reply

jstoner
Staff
Forum|alt.badge.img+22
  • Staff
  • October 21, 2024