I have a bunch of Yara rules that I would like to run on demand using the Yara table in Osquery. Is it possible to use the sigfile parameter, and if so, where should the file be stored so that Osquery finds the sigfile when running the query? Also, how should the sigfile be formatted?
Regards,
Arb