How Detection Engineers and SOC Teams Actually Test YARA Rules
Автор: Motasem Hamdan
Загружено: 2026-02-17
Просмотров: 371
Описание:
Most YARA rules look powerful on paper. But how many actually detect real-world malware? In this video, I walk you through a complete detection engineering workflow taking a static YARA rule and validating it against live malware samples using ANY.RUN’s Threat Intelligence Lookup.
You’ll learn:
• The anatomy of a strong YARA rule (meta, strings, condition)
• Why unvalidated rules create false confidence in SOC environments
• How to test your rule against real-world malware
• How to identify false positives
• How to uncover unexpected malware families
• How to refine detection logic like a true detection engineer
***
Brand collaborations and sponsorships
https://motasem-notes.net/advertise/
****
Store
https://buymeacoffee.com/notescatalog...
Instagram
/ motasem.hamdan.tech
TikTok
/ motasemhamdan0
Patreon
/ motasemhamdan
Instagram
/ motasem.hamdan.tech
Google Profile
https://maps.app.goo.gl/eLotQQb7Dm6ai...
LinkedIn
[1]: / motasem-hamdan-7673289b
[2]: / motasem-eldad-ha-bb42481b2
Twitter
/ manmotasem
Facebook
/ motasemhamdantty
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: