Actions56
- Acquisition Actions
- Asset Actions
- Baseline Actions
- Case Actions
- InterACT Actions
- Organization Actions
- Repository Actions
- Task Actions
- Triage Rule Actions
- User Actions
Triage Rule → Create Triage Rule
AI-generatedOverview
This node operation allows users to create a triage rule within the Binalyze AIR system. Triage rules are used to automate the process of identifying and categorizing security events or incidents based on specific criteria defined in the rule. This operation supports different rule engines such as YARA, Sigma, and Osquery, enabling flexible rule definitions for various detection needs. It is beneficial in scenarios where automated threat detection and response are required, such as in cybersecurity incident management or endpoint monitoring.
Use Case Examples
- Creating a YARA rule to detect specific malware signatures on endpoints.
- Defining a Sigma rule to identify suspicious log events across an organization's network.
- Using an Osquery rule to monitor system configurations and detect anomalies.
Properties
| Name | Meaning |
|---|---|
| Rule Engine | Specifies the engine type (YARA, Sigma, or Osquery) used for the triage rule. |
| Rule Description | A textual description of the triage rule, which must contain only alphanumeric characters, spaces, hyphens, underscores, or the at sign (@). This helps identify the purpose or details of the rule. |
| Rule Content | The actual content or definition of the triage rule, written according to the selected engine's syntax (YARA, Sigma, or Osquery). This defines the detection logic. |
| Search In | Specifies where to search when running the triage rule (applicable only for YARA engine). Options include searching the file system, memory, or both. |
| Additional Fields | Optional additional fields for the triage rule, including organization association and tag IDs. Organization can be selected by list, ID, or name, and tag IDs can be provided as a comma-separated string. |
Output
JSON
id- Unique identifier of the created triage rule.engine- The engine type used for the triage rule.description- Description of the triage rule.rule- Content of the triage rule.searchIn- Where the rule is applied when using the YARA engine.organizationId- Identifier of the organization associated with the triage rule.tagIds- Comma-separated list of tag IDs associated with the triage rule.
Dependencies
- Requires an API key credential for authentication with the Binalyze AIR platform.
Troubleshooting
- Ensure the rule description matches the required regex pattern to avoid validation errors.
- Verify that the rule content is correctly formatted according to the selected engine's syntax to prevent rule creation failures.
- Check that the organization ID is valid and accessible by the user to avoid permission issues.