Skip to content

Add remote YARA language to pricing chart#25181

Merged
noahtalerman merged 4 commits intodocs-v4.63.0from
sgress454/remote-yara-language
Jan 7, 2025
Merged

Add remote YARA language to pricing chart#25181
noahtalerman merged 4 commits intodocs-v4.63.0from
sgress454/remote-yara-language

Conversation

@sgress454
Copy link
Copy Markdown
Contributor

relates to #14899

Copy link
Copy Markdown
Member

@noahtalerman noahtalerman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @sgress454! Looking good.

Left some request changes below.

friendlyName: Scan files for zero days and malware signatures
description: Use YARA signatures to report and trigger automations when zero days, malware, or unexpected files are detected on a host.
description: Use YARA signatures to report and trigger automations when zero days, malware, or unexpected files are detected on a host. YARA rules can be deployed remotely and privately.
documentationUrl: https://fleetdm.com/tables/yara
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
documentationUrl: https://fleetdm.com/tables/yara
documentationUrl: https://fleetdm.com/guides/remote-yara-rules

I think let's point to the guide in the top-level URL. This way, if someone clicks to learn more on the pricing page they'll be taken to the guide:
Screenshot 2025-01-06 at 5 37 11 PM

Also, it looks like the guide has a link to the table (old URL) 👍
Screenshot 2025-01-06 at 5 38 10 PM

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done

- industryName: Malware detection (YARA/custom IoCs) # TODO: consider: technically more than YARA, consider generalizing this and including the concept of comparing known binary hashes and other IoCs (either via live query or in the data lake to compare threat intel feed)
friendlyName: Scan files for zero days and malware signatures
description: Use YARA signatures to report and trigger automations when zero days, malware, or unexpected files are detected on a host.
description: Use YARA signatures to report and trigger automations when zero days, malware, or unexpected files are detected on a host. YARA rules can be deployed remotely and privately.
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
description: Use YARA signatures to report and trigger automations when zero days, malware, or unexpected files are detected on a host. YARA rules can be deployed remotely and privately.
description: Deploy YARA signatures (rules) to report and trigger automations when zero days, malware, or unexpected files are detected on a host.

Small copy tweak. I think users expect to be able to deploy "remotely and privately" (the new way) even though you can technically deploy rules publicly (old way). I think let's make the new way as the best practice.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gotcha. I was thinking this was a selling point since it seems that only Fleet supports it right now, so seemed like it was worth explicitly pointing out.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair point. I tweaked the langauge a bit but left in the second sentence.

Comment on lines +962 to +963
- description: Deploy YARA rules to your own private server that Fleet authenticates with.
moreInfoUrl: https://fleetdm.com/guides/remote-yara-rules
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- description: Deploy YARA rules to your own private server that Fleet authenticates with.
moreInfoUrl: https://fleetdm.com/guides/remote-yara-rules

I think we can cut this because we're updating the top level URL to the guide. Also it's less to maintain if we pull it out.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done

@noahtalerman noahtalerman merged commit c846e30 into docs-v4.63.0 Jan 7, 2025
@noahtalerman noahtalerman deleted the sgress454/remote-yara-language branch January 7, 2025 14:54
sgress454 added a commit that referenced this pull request Jan 7, 2025
rachaelshaw pushed a commit that referenced this pull request Jan 7, 2025
This PR cherry-picks a couple of docs changes I added to the docs-4.63.0
branch. These changes were approved and merged in
#25181 and
#25189, before I belatedly asked
whether that was the correct process.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants