Skip to main content

Team,

Could you please help me understand how to get into Yara-L using this rule

Potential beaconing activity ASIM Network Session schema | Microsoft Sentinel Analytic Rules

Take a look at this previous post to see if it helps:

Understanding YARA-L Rules