By default, every custom YARA rule has an integer weight associated with it, ranging from 0 to 100. During static analysis, when a YARA rule match is made, the corresponding weight of the matched rule is added to the overall score of the file deemed malicious. As more YARA rules are matched, the rule with the highest weight is used. If no weight is provided for a YARA rule, the default YARA weight is used.
Trellix reports when the rule matches (if it is one of the first five rules matched). YARA rules with a weight of 0 are generally used for informational purposes (for example, when a file is a malformed Win32 portable executable).
Note
You cannot configure YARA rules using the sensor CLI.
Prerequisites
An established connection between the Network Security appliance and the Internet.
Administrator or Operator access to the Network Security appliance.
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Specify the limit for YARA matches.
hostname (config) # yara weight default <100 +/->
where:
<100 +/->is an integer between 0 and 100.The following example configures a YARA weight of 75:
hostname (config) # yara weight default 75