Skip to content

capa and YARA

capa (FLARE's capability detector) and YARA reach a run in three places, so a run can have their answers even with no static provider at all.

Where What runs Written to the ledger as
The triage pack yara_scan and capa (under the static provider's budget), before any analyst starts the pack's own entries
The analysis sidecar the capa and yara_scan tools, which an agent calls the agent's calls
The capa_yara static provider two deterministic passes, no tools and no model loop entries under the agent id capa_yara

The capa_yara provider

core.static.provider          = capa_yara
core.static.capa.rules_dir    = data/capa-rules
core.static.yara.rules_dir    = data/yara_rules
Setting Default Notes
core.static.capa.rules_dir data/capa-rules capa's rules.
core.static.capa.signatures_dir data/capa-signatures capa's library signatures.
core.static.capa.timeout_seconds 300 capa's budget.
core.static.capa.backend auto auto, vivisect, pefile or binja.
core.static.yara.rules_dir data/yara_rules The operator's own rule directory, scanned only by this provider.
core.static.yara.timeout_seconds 60 The scan's budget.

Both libraries are optional extras of the package, capa (flare-capa) and yara (yara-python): uv sync --extra capa --extra yara. The backend image installs the yara and tools extras. A missing library costs the provider its evidence, with one warning, rather than failing a job.

The rule corpora of the analysis sidecar

The Sigma and YARA corpora the analysis tool server scans with are named in that server's env (Settings → Tool servers → analysis → env):

Name What it names Default
MALJAN_SIGMA_RULES_DIR Directory of Sigma rule YAML, loaded recursively. data/sigma_rules
MALJAN_YARA_RULES_DIR The YARA rule file the scan compiles. data/yara_ttp_rules.yaml

A path that does not exist means an empty corpus and no matches, not a failure. A YARA pattern must be a fact about a sample rather than a word that describes one; how the shipped rules are written, and how a rule asserts nothing when it cannot be that specific, is in Rule corpora.

A rule match is not a claim

A technique that only a deterministic rule asserted, and no analyst claimed, is marked as such in the report's ATT&CK table — "rule match only" with the rule and its string count — and grounds no capability word in the report's prose. capa's place in the triage pack is described in The triage pack.