diff --git a/apparmor.d/profiles-s-z/yara b/apparmor.d/profiles-s-z/yara new file mode 100644 index 00000000..487f6a98 --- /dev/null +++ b/apparmor.d/profiles-s-z/yara @@ -0,0 +1,28 @@ +# apparmor.d - Full set of apparmor profiles +# Copyright (C) 2025 Zane Zakraisek +# SPDX-License-Identifier: GPL-2.0-only + +abi , + +include +include + +@{exec_path} = {/usr,}/bin/yara +profile yara @{exec_path} { + include + + @{exec_path} mr, + + capability dac_override dac_read_search, + + if $ANTIVIRUS_CAN_PTRACE { + ptrace (read, trace), + capability sys_ptrace, + } + + /{,**} r, + + deny capability sys_admin, + + include if exists +}