EDR: Yara Connector Continues to Send Alerts After Rules Have Been Removed
search cancel

EDR: Yara Connector Continues to Send Alerts After Rules Have Been Removed

book

Article ID: 287418

calendar_today

Updated On:

Products

Carbon Black Hosted EDR (formerly Cb Response Cloud)

Issue/Introduction

  • Alerts continue to fire despite rules being removed.

Environment

  • EDR Server: All Supported Versions
  • CB-Yara-Connector/Manager: All Supported Versions

Cause

  • Binaries are tagged in SOLR and until they are untagged they will continue to alert upon rules.

Resolution

  1. Stop the cb-yara-connector service:
systemctl stop cb-yara-connector
  1. Remove the Yara Connector database:
rm /var/cb/data/cb-yara-connector/feed_db/binary.db
  1. Run feed scrubber and scrub existing feed, as per EDR: How to tag/untag feed binaries and events.  There is no need to retag the events as mentioned in the article.
/usr/share/cb/cbfeed_scrubber --untag yara
  1. Restart the  EDR services and then start the cb-yara-connector service:
systemctl restart cb-enterprise
systemctl start cb-yara-connector