19 Comments

Hi, im stuck with the same problem, did u figured it out?

Expand full comment

Thank you so much Eric for this walkthrough, It’s indeed a great resource for gaining hands-on experience.

Expand full comment

I encountered same issue, what I did was to delete the YARA rules as well as D&R Rules I created , then created it again. It worked for me.

Expand full comment

Is your logon account name something else, like Jon or Ed or Eric? Maybe you need to change 'User' in the file path to the user's profile name where the download is.

Expand full comment

When trying to input the command in the console I put it exactly like in the tutorial says but I keep getting "failed to parse task [{yara_scan hive://yara/sliver -f C:\Users\User\Downloads\FUZZY_MIDI.exe yara_scan hive://yara/sliver -f C:\Users\User\Downloads\FUZZY_MIDI.exe}]: lc_error_code:FAILED_GETTING_YARA_RULE"

What do you think might be the issue? I tried double checking my YARA and D&R rules having the VM running and have the payload exucted and still telling me the same thing :( tried disabling other rules but haven't had any luck

Expand full comment

When selecting YARA Rules it tells me: Missing Permission Ask the administrator to give you yara.get permission.

Expand full comment