Files
blue-team-tools/rules/windows/builtin
Nick Moore 0312c481d9 Change rules using all of required-lists to |all
When a Sigma rule writer wants to create a list of values where all of
them must be matched for the rule to trigger, the approach used
previously was to have an `all of` condition for a single selector.
However, this has now changed, and the new approach is to use an empty
key and the |all modifier (i.e., `'|all'`).

This commit (tries to) identify all the rules that used the old
approach and modifies them to use the new approach instead.

See SigmaHQ/sigma-specification#53 for further discussion.
2023-01-23 14:37:25 +00:00
..
2023-01-12 18:37:35 +01:00
2022-10-25 11:08:51 +02:00
2023-01-19 22:07:31 +01:00
2022-10-25 11:08:51 +02:00
2023-01-17 01:13:50 +01:00
2023-01-07 08:52:11 +01:00
2023-01-02 12:05:54 +01:00
2023-01-17 19:14:32 +01:00
2022-12-28 16:17:46 +01:00
2022-10-25 11:08:51 +02:00
2022-10-25 20:03:11 +02:00
2023-01-20 11:39:08 +01:00
2022-09-28 06:32:34 +09:00
2022-10-25 11:08:51 +02:00
2023-01-02 15:49:45 +01:00
2023-01-19 00:49:32 +01:00
2023-01-13 18:01:10 +01:00
2022-10-25 11:08:51 +02:00
2022-12-27 12:29:10 +01:00
2022-10-25 11:08:51 +02:00