Qualys EDR Yara Rules Configuration with TBUS Scoping
Limited Customer Release Notes
August 11, 2026
Tag-Based User Scoping for Yara Rules
You can now limit which imported YARA rules are visible to you based on your user tag scope, so you only see the rules relevant to your own tag instead of every YARA rule imported across the subscription.
Previously, every imported YARA rule was visible to everyone on the account, since rules were not tied to a specific tag. Now, each request for YARA rules is checked against your UID and customer tag, so only rules imported within your tag scope are shown. This applies to rules imported before this release too. Existing rule records have been updated with the new tag field, so older rules are filtered the same way as new ones. Accounts with full administrative access still see every imported YARA rule, regardless of tag scope.
Tag-based scoping is applied on the Yara Rules tab, under Configurations page.
Import Yara Rule with Tag-based Scoping
Tag-based scoping applies automatically to rules you import, with no separate setup required. To import a rule:
- Go to Configuration > Yara Rules tab, and click New Rule.
- On the General Settings step, drag and drop your YARA rule file, or click Browse to select it from your local machine, and click Next.
- On the Review and Confirm step, review the rule name, description, and content captured from the uploaded YARA rule, and click Submit to import the rule.
The rule gets added to the Yara Rules tab.
Once tag-based scoping is enabled for your account, only accounts whose tag scope matches the rule can see the rule on the Yara Rules tab. Accounts with full administrative access can see all imported rules of all the accounts under the admin scope.
Refer to the following screenshot of the Yara Rules tab, showing all the rules imported under different tag scopes for the account having full administrative access.

To enable this feature for your account, contact your Technical Account Manager (TAM).