Files
blue-team-tools/rules/windows/sysmon
Maxime Lamothe-Brassard 25d3a5a893 Remove "condition" from global rule.
The condition field in this rule was in the global section which overwrote the condition in sub-rules and generated FPs. For example, once Sigma read the rule, the bottom sub-rule's "condition" was overwritten with "1 of them".
2020-05-17 12:44:57 -07:00
..
2020-02-20 23:00:16 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-04-14 13:40:34 +02:00
2020-03-31 15:22:00 +02:00