Actions56
- Acquisition Actions
- Asset Actions
- Baseline Actions
- Case Actions
- InterACT Actions
- Organization Actions
- Repository Actions
- Task Actions
- Triage Rule Actions
- User Actions
Triage Rule → Validate Triage Rule
AI-generatedOverview
This node validates a triage rule based on the selected rule engine (YARA, Sigma, or Osquery). It is useful in scenarios where users need to ensure that their triage rules are correctly formatted and valid before applying them in security or incident response workflows. For example, a security analyst can use this node to validate a YARA rule to detect malware patterns or a Sigma rule for log event correlation.
Use Case Examples
- Validating a YARA rule to detect specific malware signatures.
- Validating a Sigma rule for log event correlation in a SIEM system.
- Validating an Osquery rule for endpoint monitoring.
Properties
| Name | Meaning |
|---|---|
| Rule Engine | The engine type for the triage rule, which can be YARA, Sigma, or Osquery. |
| Rule Content | The content of the triage rule to be validated, written in the syntax of the selected engine (YARA, Sigma, or Osquery). This is the actual rule text that will be checked for correctness. |
Output
JSON
validationResult- The result of the triage rule validation, indicating whether the rule is valid or contains errors.errors- Details of any errors found during the validation of the triage rule.
Dependencies
- Requires an API key credential for authentication to the AIR platform.
Troubleshooting
- If the rule content is empty or improperly formatted, the node may throw a validation error. Ensure the rule content matches the syntax of the selected engine.
- If the API key credential is missing or invalid, authentication errors will occur. Verify the credential configuration.
- Errors returned from the AIR platform during validation will be included in the output; review these errors to correct the rule content.