AIR icon

AIR

Manage Binalyze AIR resources

Triage Rule → Update Triage Rule

AI-generated

Overview

This node operation updates an existing triage rule in the Binalyze AIR system. It allows users to modify the rule's engine type (YARA, Sigma, or Osquery), description, content, and search scope (file system, memory, or both). Additionally, users can specify the organization associated with the triage rule. This operation is useful for maintaining and refining triage rules used in endpoint investigations and threat detection workflows.

Use Case Examples

  1. Updating a YARA triage rule to change its search scope from file system to memory.
  2. Modifying the description and content of a Sigma triage rule to improve detection accuracy.
  3. Assigning a triage rule to a specific organization for targeted investigations.

Properties

Name Meaning
Triage Rule The specific triage rule to update, selectable by list or by ID.
Rule Engine The engine type for the triage rule, which can be YARA, Sigma, or Osquery.
Rule Description A description of the triage rule, restricted to alphanumeric characters, spaces, hyphens, underscores, and the at sign (@).
Rule Content The content of the triage rule based on the selected engine (YARA, Sigma, or Osquery).
Search In Where to search when running the triage rule, applicable only for YARA engine. Options include file system, memory, or both.
Additional Fields Optional additional fields for the triage rule update, including the organization to which the rule belongs. Organization can be selected from a list, by ID, or by name.

Output

JSON

  • id - The unique identifier of the updated triage rule.
  • engine - The engine type of the updated triage rule (YARA, Sigma, or Osquery).
  • description - The description of the updated triage rule.
  • rule - The content of the updated triage rule.
  • searchIn - The search scope for the triage rule when using the YARA engine (file system, memory, or both).
  • organizationId - The organization ID associated with the triage rule.

Dependencies

  • An API key credential for authenticating with the Binalyze AIR API.

Troubleshooting

  • Ensure the triage rule ID is valid and matches the required pattern (letters, numbers, hyphens, underscores).
  • Verify that the rule description only contains allowed characters (alphanumeric, spaces, hyphens, underscores, @).
  • Check that the rule content matches the syntax requirements of the selected engine (YARA, Sigma, or Osquery).
  • Confirm that the organization ID is a positive number or 0 for the default organization.

Discussion