Skip to main content

Command Overview

beacon rules add installs a local .rule.yaml file or a directory of rule files into the local threat-rule store.
Command syntax
Beacon validates rules before installing them. Installed rules become active for future beacon scan runs.

Examples

Install all rules from a local directory:
Install local rules
Install one rule file:
Install one rule
Overwrite an existing rule with the same id:
Overwrite an existing rule
Install into the system-mode rule store:
Install system-mode rules

Flags

beacon rules lint

Validate rules and fixtures before installing.

beacon rules list

Confirm which rules are active.