Monitor a YARA rule

Learn how to continuously monitor YARA rules for newly matched infrastructure.

Monitoring a YARA rule continuously evaluates Validin’s collected HTTP telemetry and updates the All Matches tab whenever new content matches the rule, allowing you to review recent detections.

You can also enable retrohunting to check for historical matches.

📘

Rule validity

Monitoring depends on the rule’s validity. Rules with syntax errors or unresolved dependencies cannot be monitored.

Enable monitoring for a YARA rule

To begin monitoring a rule, open the rule and configure tracking.

  1. Open a Project.
  2. Select the YARA Rules tab.
  3. Select a rule to open its detail view.
  4. Use the Tracking control to enable monitoring.
  5. Confirm the rule saves with an active tracking version, displayed as Tracking vX.

Once enabled, Validin evaluates new HTTP responses against the rule as they enter the platform.

👍

Rule eligibility

Ensure your rule has a stable condition with low false positives before enabling monitoring to reduce noise.

Review monitored results

To inspect monitored matches, use the rule’s built-in views.

  1. Open the YARA rule being monitored.
  2. Select the All Matches tab to view live match results.
  3. Review newly observed entries using the First Seen and Last Seen timestamps.

Results appear in a table with the following fields:

FieldDescription
Host/IPThe host or resolved IP address where a match was recorded.
PortDestination port for the HTTP request.
Response/PathThe path and URL segment where the match occurred.
TitleExtracted HTML title of the matched page.
Bytes ReceivedSize of the returned payload.
First SeenWhen the matched content was first observed.
Last SeenMost recent observation of the matched resource.

Selecting a row opens the enriched HTTP event. This includes HTML source, certificate metadata, JARM fingerprint, response banners, and additional artifacts useful for investigation.

Monitor historical matches with retrohunting

To extend monitoring beyond new telemetry, run periodic retrohunts.

  1. Open the YARA rule.
  2. Select New Retro to initiate a historical scan.
  3. Review results in the Retrohunt section of the rule.
📘

Detecting infrastructure shift

Retrohunting supplements live monitoring by identifying older artifacts matched by the rule.

Update a monitored rule

Monitoring continues only if the rule remains valid and saved. When updating a monitored rule, Validin applies version control to preserve the previous tracking state. This ensures rule evolution is captured while maintaining monitoring continuity.

  1. Edit the YARA rule in the Rule Editor.
  2. Select Save to update the rule.
  3. Confirm the updated tracking version (for example, Tracking v2).

Stop monitoring a rule

Monitoring can be disabled without removing the rule from the Project.

Monitoring stops immediately and no further matches are recorded.

  1. Open the YARA rule.
  2. Select the Tracking control to disable monitoring.
  3. Confirm that tracking information is no longer displayed.


What’s Next

Work with returned YARA results