From dabc759136a974ff85249564db37e415e7e00d74 Mon Sep 17 00:00:00 2001 From: Justin Ellison Date: Thu, 26 Mar 2020 09:13:52 -0500 Subject: [PATCH] Eliminate title collision Fixing the problem described in HELK here: https://github.com/Cyb3rWard0g/HELK/issues/442 where when running sigmac to generate elastalert rules, this rule has a title collision with another rule in the same directory and causes elastalert to fail to start. --- rules/windows/process_creation/win_apt_bear_activity_gtr19.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/process_creation/win_apt_bear_activity_gtr19.yml b/rules/windows/process_creation/win_apt_bear_activity_gtr19.yml index b8062c123..d3d160ee3 100644 --- a/rules/windows/process_creation/win_apt_bear_activity_gtr19.yml +++ b/rules/windows/process_creation/win_apt_bear_activity_gtr19.yml @@ -1,4 +1,4 @@ -title: Judgement Panda Exfil Activity +title: Judgement Panda Credential Access Activity id: b83f5166-9237-4b5e-9cd4-7b5d52f4d8ee description: Detects Russian group activity as described in Global Threat Report 2019 by Crowdstrike references: