AIR icon

AIR

Manage Binalyze AIR resources

Triage Rule → Validate Triage Rule

AI-generated

Overview

This node validates a triage rule based on the selected rule engine (YARA, Sigma, or Osquery). It is useful in scenarios where users need to ensure that their triage rules are correctly formatted and valid before applying them in security or incident response workflows. For example, a security analyst can use this node to validate a YARA rule to detect malware patterns or a Sigma rule for log event correlation.

Use Case Examples

  1. Validating a YARA rule to detect specific malware signatures.
  2. Validating a Sigma rule for log event correlation in a SIEM system.
  3. Validating an Osquery rule for endpoint monitoring.

Properties

Name Meaning
Rule Engine The engine type for the triage rule, which can be YARA, Sigma, or Osquery.
Rule Content The content of the triage rule to be validated, written in the syntax of the selected engine (YARA, Sigma, or Osquery). This is the actual rule text that will be checked for correctness.

Output

JSON

  • validationResult - The result of the triage rule validation, indicating whether the rule is valid or contains errors.
  • errors - Details of any errors found during the validation of the triage rule.

Dependencies

  • Requires an API key credential for authentication to the AIR platform.

Troubleshooting

  • If the rule content is empty or improperly formatted, the node may throw a validation error. Ensure the rule content matches the syntax of the selected engine.
  • If the API key credential is missing or invalid, authentication errors will occur. Verify the credential configuration.
  • Errors returned from the AIR platform during validation will be included in the output; review these errors to correct the rule content.

Discussion