Manually trigger rescan of known files to apply new Yara Rule tags
search cancel

Manually trigger rescan of known files to apply new Yara Rule tags

book

Article ID: 423146

calendar_today

Updated On:

Products

Carbon Black App Control

Issue/Introduction

When a new Yara Rule is created and the checkbox to Rescan known files is not selected, the new yara tags are not applied to existing files, but only to newly created files.

Currently, there is no mechanism in the web console to trigger manual rescanning needed to apply new Yara tags to existing files.

Environment

App Control Server: All Supported Versions

Resolution

  1. Go to > https://AppCServer/Shepherd_config.php > ShowAllProps > Set it to: true > Change > Navigate away from the page
  2. Reopen >  https://AppCServer/Shepherd_config.php > YaraFileVersion > Increment the value by 1 (e.g. 5+1=6) > Change
  3. Open SQL Mgmt Studio with the service account and execute the query (first, update @yaraVersion to match the new version number, e.g. @yaraVersion=6):
    USE das; Exec dbo.API_InsertYaraVersionDetails @yaraVersion=6,@ccLevel=2,@ccHourStart=0,@ccHourEnd=0
  4. Go to >  https://AppCServer/Shepherd_config.php > TriggerYaraDownload > Set it to: true > Change
    • Warning: this will trigger CC check of known files (low level) on all agents, so it is best done after hours.
    • Optional: go to > https://AppCServer/Shepherd_config.php > ShowAllProps > Set it to: false > Change