create_triage_rule
Generate a new triage rule using YARA content, specify search locations, and assign to organizations for efficient digital forensics and incident response.
Instructions
Create a new triage rule
Input Schema
Name | Required | Description | Default |
---|---|---|---|
description | Yes | A descriptive name for the triage rule | |
engine | Yes | Rule engine to use, e.g., "yara" | |
organizationIds | No | Organization IDs to associate with this rule. Defaults to [0] | |
rule | Yes | The YARA rule content | |
searchIn | Yes | Where to search, e.g., "filesystem" |