Replies: 2 comments 8 replies
-
|
I am not sure I understand correctly. The rule in question just uses a keyword search and does not specify on which EventID it should match. I don't see an issue with the rule. What would the |
Beta Was this translation helpful? Give feedback.
8 replies
-
|
This has been resolved and sigma rules in the repo have been modified. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Ref SigmaHQ/sigma#3622
Some Windows Eventid don't have field name.
datafield name should be add to Taxonomy_1_2_0.md.Beta Was this translation helpful? Give feedback.
All reactions