Skip to main content

Command Overview

beacon rules pull downloads a rule file or rule pack from an explicit URL and installs valid rules into the local store.
Command syntax
This is the only beacon rules command that reaches the network, and only when you run it. Beacon never fetches rules on its own. The full Asymptote threat-rule pack is published as a versioned threat-rules.tar.gz asset on each Agent Beacon GitHub release.

Supported inputs

beacon rules pull accepts: Downloaded tarballs only install .rule.yaml entries. Archive entries containing path traversal elements are rejected before install.

Examples

Pull a rule pack:
Pull a rule pack
Pull one rule file:
Pull one rule file
Overwrite an existing rule with the same id:
Overwrite existing rules
Install into the system-mode rule store:
Pull system-mode rules

Flags

beacon rules lint

Validate a rule pack before publishing or installing.

beacon rules list

Confirm the installed active rules.