https://github.com/osquery/osquery logo
Title
m

mike maxwell

05/17/2021, 6:38 PM
but the SIGFILE is only displaying the TOP level yara file, making it difficult to know exactly what Yara file was triggered. Thank you for any help and consideration.
a

Akshay Kumar

05/18/2021, 4:59 PM
Hi Mike, Sigfile column only shows the top-level yara file and not the include file that triggered the match. It also has
matches
column that lists the Yara matches.
It uses
libyara
interface for scanning which does not provide a way to get which include yara file the matches belong to. It only tells you the matches based on top-level sigfile.
m

mike maxwell

05/19/2021, 4:25 PM
Thank you for the reply