If you have existing custom detection rules, you can quickly and easily import them into Helix. For example, you might have rules that you use with a particular third party product, or rules specific to your organization's requirements. Being able to import these rules saves you time as you don't have to re-create the rule from scratch, or copy and paste the rule.
Note
You can only import custom detection rules in YAML format.
You can import a single custom detection rule, or a file with multiple rules. Imported rules are validated, and any errors are displayed along with an explanation of what went wrong. Incorrectly formatted rules are not imported into Helix.
To import detection rules:
On the Rules page, click Import Rules.
Click Choose File..., select the file you want to import, and then click Upload File.
Valid rules are imported into Helix and error messages explain why any rules are invalid. Repeat this step for any other files you want to import.
When you have uploaded all your detection rules, click Close.
To export detection rules:
On the Rules page, do one of the following:
To export a single rule, at the end of the row click More Options
> Export > Export Rule.To export multiple rules, select the checkbox next to each rule and click Actions > Export > Export Rule.
Note
You cannot export Trellix rules.