remove TAB from cli escape as it's currently unsupported in sigmac

This commit is contained in:
ecco 2019-09-23 04:46:10 -04:00
parent 9630635e25
commit c2868f6e03

View File

@ -18,7 +18,7 @@ logsource:
detection:
selection:
CommandLine:
- <TAB>
# - <TAB> # no TAB modifier in sigmac yet, so this matches <TAB> (or TAB in elasticsearch backends without DSL queries)
- ^h^t^t^p
- h"t"t"p
condition: selection