Chad Priest

05/14/2021, 4:09 PM
Hello - We are looking to run Yara rules on windows machines from FleetDM and came across the Polylogyx osq-ext-bin repo (found here: https://github.com/polylogyx/osq-ext-bin) for our SASS offering but it seems like we won't be able to use this due to the license agreement for our commercial product. I was wondering if anyone might know of an alternative to this?
Mike Myers

Mike Myers

05/14/2021, 8:03 PM
have you looked at the Yara tables in osquery core? https://osquery.io/schema/4.8.0/#yara