Chainsaw: save custom rule
chainsaw_save_ruleSave an analyst-authored Chainsaw detection rule to the custom rules directory and lint it, enabling hunting with extra_rules=['custom'].
Instructions
Save an analyst-authored Chainsaw rule into the custom rules directory.
Saved rules are hunted with extra_rules=['custom']. The file is linted before the result is returned; a failing lint still leaves the file in place so it can be fixed with another save using overwrite=true.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| lint | No | Run chainsaw lint on the saved file. | |
| name | Yes | File name without directories, e.g. suspicious_rdp_from_workstation | |
| overwrite | No | Replace an existing custom rule. | |
| yaml_text | Yes | Complete Chainsaw rule YAML with title, group, description, authors, kind, level, status, timestamp, fields and filter. See the chainsaw://docs/rule-format resource. |