Qualys CIPS Vulnerability Data Field Value Update for Cloud Storage Integrations

Limited Customer Release Notes

July 06, 2026

What is Yara Rules Configuration with RBAC scoping?

Yara Rules Configuration with RBAC Scoping enables role-based control over YARA rule management in Qualys EDR.

This enhancement introduces granular permissions to regulate access to view, create, edit, and delete Yara rules. Previously, access to YARA rule operations was not fine-grained. With this update, access can be aligned with defined roles to enforce least-privilege principles and improve governance of the rule lifecycle.

Benefits

The Yara Rules Configuration with RBAC Scoping provides the following benefits:

  • Granular access control by enabling precise permissions for viewing, creating, editing, and deleting rules.
  • Reduces the risk of unauthorized changes
  • Enforces separation of privileges
  • Supports role-based governance, resulting in improved security, compliance, and streamlined rule management.

What are the new required permissions for Yara Rules Configuration with RBAC Scoping in Qualys EDR?

The following new permissions are available that can be configured within Role Management:

Permission Description

EDR YARA Rule View

Enables visibility of the Yara Rules tab and existing rules. This permission is mandatory for the Create and Delete permissions.

EDR YARA Rule Create

Allows creating and editing Yara rules. Requires View permission.

EDR YARA Rule Delete

Allows deletion of Yara rules. Requires View permission.

Permission Behavior

The new permissions have the following behavior:

  • The Yara Rules tab is visible only when EDR Yara Rule View is enabled.
  • The New Rule button for creating a new rule, the edit existing rule actions, and the Save button are available only when both View and Create permissions are enabled.
  • The Delete button is available only when both View and Delete permissions are enabled.
  • Create and Edit capabilities are combined under a single permission for simplified management.
  • Delete is separated to enforce stricter control over destructive actions.

How to Configure Yara Rule Permissions?

To configure Yara rule permissions, perform the following steps:

  1. From the module picker, select Administration.

  2. Navigate to Users > Roles.
  3. Create a new role or modify an existing role.
  4. In the Edit Role window, navigate to Permissions > Endpoint Detection and Response > EDR Yara Rule Permissions, and select the required permissions:
    • EDR Yara Rule View
    • EDR Yara Rule Create
    • EDR Yara Rule Delete
  5. Click Next. 

  6. In the Review and Confirm window, click Save.

After assigning the permissions, you can access the Yara rules.

To access the Yara rules, navigate to EDR > Configuration > Yara Rules