Roberto Rodriguez
|
a0486edeea
|
Field-Index Mapping File & SIGMA Rules Field names fix
+ Updated HELK field-index mapping file
+ After going through all the fields with 'fieldlist' output, I found a few rules that fixed.
|
2018-12-11 09:27:26 +03:00 |
|
Sherif Eldeeb
|
23eddafb39
|
Replace "logsource: description" with "definition" to match the specs
|
2018-11-15 09:00:06 +03:00 |
|
Florian Roth
|
9cb78558d3
|
Rule: excluded false positives in rule
|
2018-09-03 12:02:42 +02:00 |
|
Florian Roth
|
b57f3ded64
|
Rule: GRR false positives
|
2018-09-03 11:50:34 +02:00 |
|
Florian Roth
|
2a0fcf6bea
|
Rule: PowerShell encoded command JAB
|
2018-09-03 10:08:29 +02:00 |
|