mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
remove TAB from cli escape as it's currently unsupported in sigmac
This commit is contained in:
parent
9630635e25
commit
c2868f6e03
@ -18,7 +18,7 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
- <TAB>
|
||||
# - <TAB> # no TAB modifier in sigmac yet, so this matches <TAB> (or TAB in elasticsearch backends without DSL queries)
|
||||
- ^h^t^t^p
|
||||
- h"t"t"p
|
||||
condition: selection
|
||||
|
Loading…
Reference in New Issue
Block a user