-
I use TagCheck service to mark some indicators - and this is a great feature! However, I could potentially lower the number of false positives if I could filter out given file names and types (in my use case, the file name often matters more than type). And here comes my question: is it already supported by TagCheck? I'm not sure if I don't miss something: generally, TagCheck seems to get only data from So, I'm unsure if I didn't miss anything. Is the case of matching name and/or type of the submitted file already supported? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
After taking a look at the service, it does seem that As to your main question about whether or not the filename or AL-identified file type can be used in a YARA rule definition as an external, I would say the answer is yes because the service is aware of these properties per the TaskMessage model. |
Beta Was this translation helpful? Give feedback.
-
Since the last comment, I will close this discussion for now, feel free to re-open if needed. 😁 |
Beta Was this translation helpful? Give feedback.
Since the last comment,
file_name
has been added to YARA_EXTERNALS per your PR and you've fixed the handling of the externals variable (thanks! 🤓).I will close this discussion for now, feel free to re-open if needed. 😁