mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
1dec1a49fa
Mapped OriginalFileName to ProcessVersionInfoOriginalFileName in DeviceProcessEvents. Tested and works for rules such as https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/win_renamed_binary.yml |
||
---|---|---|
.. | ||
backends | ||
config | ||
parser | ||
__init__.py | ||
configuration.py | ||
filter.py | ||
merge_sigma.py | ||
output.py | ||
sigma2attack.py | ||
sigma2genericsigma.py | ||
sigma2misp.py | ||
sigma_similarity.py | ||
sigma_uuid.py | ||
sigma-similarity.py | ||
sigma-uuid.py | ||
sigmac.py | ||
tools.py |