Files
blue-team-tools/rules/linux/builtin
Nick Moore 0312c481d9 Change rules using all of required-lists to |all
When a Sigma rule writer wants to create a list of values where all of
them must be matched for the rule to trigger, the approach used
previously was to have an `all of` condition for a single selector.
However, this has now changed, and the new approach is to use an empty
key and the |all modifier (i.e., `'|all'`).

This commit (tries to) identify all the rules that used the old
approach and modifies them to use the new approach instead.

See SigmaHQ/sigma-specification#53 for further discussion.
2023-01-23 14:37:25 +00:00
..
2023-01-07 08:52:11 +01:00
2023-01-07 08:52:11 +01:00
2023-01-07 08:52:11 +01:00
2023-01-07 08:52:11 +01:00
2023-01-05 08:14:19 +01:00
2023-01-07 08:52:11 +01:00
2023-01-07 08:52:11 +01:00
2022-10-25 08:53:44 +02:00
2022-10-25 08:53:44 +02:00
2022-11-27 19:19:27 +01:00
2022-10-25 08:53:44 +02:00
2022-10-25 08:53:44 +02:00
2022-10-25 08:53:44 +02:00
2022-10-25 08:53:44 +02:00
2023-01-06 17:28:29 +01:00
2022-10-25 08:53:44 +02:00
2022-10-25 08:53:44 +02:00