post
https://app.stairwell.com/v1/yaraRules:scan
Runs an ad-hoc YARA rule against the historical object corpus and returns the matches. Combines two discovery paths automatically: candidate-file lookup using Stairwell's partial binary indexes, and variant discovery for any SHA256/SHA1/MD5 literals named in the rule body. Results are returned synchronously when the scan finishes or when max_matches is reached.
The scan's environment scope is controlled by the request's environments field — an empty list means "every environment the caller can read." The rule is NOT persisted; use CreateYaraRule for that. This endpoint is for quick evaluation of a rule body against history.
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…
