extremeshok/clamav-unofficial-sigs

Ignore yara rules

deeztek opened this issue · 1 comments

Trying to get clamav to ignore a yara rule, in particular, YARA.invalid_trailer_structure.UNOFFICIAL due to many false positives. I've entered the following in local.ign2:

YARA.invalid_trailer_structure

but clamav seems to completely ignore it. Any idea what I'm doing wrong here?

Thanks

Trying to get clamav to ignore a yara rule, in particular, YARA.invalid_trailer_structure.UNOFFICIAL due to many false positives. I've entered the following in local.ign2:

YARA.invalid_trailer_structure

but clamav seems to completely ignore it. Any idea what I'm doing wrong here?

Thanks

Or should it be simply:

invalid_trailer_structure