From 2cecd0e6ef7ddecbf81ce5f01b2205ccfdcbb414 Mon Sep 17 00:00:00 2001 From: phantinuss <79651203+phantinuss@users.noreply.github.com> Date: Mon, 21 Feb 2022 10:27:27 +0100 Subject: [PATCH] workflow: rename steps --- .github/workflows/sigma-test.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/sigma-test.yml b/.github/workflows/sigma-test.yml index 630cb7b33..00dd1fa1b 100644 --- a/.github/workflows/sigma-test.yml +++ b/.github/workflows/sigma-test.yml @@ -51,9 +51,9 @@ jobs: tar xzf win10-client.tgz - name: Remove deprecated rules run: 'grep -ERl "^status: deprecated" rules | xargs -r rm -v' - - name: Run evtx-sigma-checker + - name: Check for Sigma matches in baseline (run evtx-sigma-checker) run: | chmod +x evtx-sigma-checker ./evtx-sigma-checker --log-source tools/config/thor.yml --evtx-path Logs_Client/ --rule-path rules/windows/ > findings.json - - name: Check for Sigma matches in baseline + - name: Show findings (exclude known FPs) run: ./github/workflows/matchgrep.sh findings.json .github/workflows/known-FPs.csv