Files
blue-team-tools/tools/sigma
tr0mb1r 27b8b85230 Update elasticsearch.py
Example:

'threshold': {
        'field': [
            'host.name',
        ],
        'value': 10,
        'cardinality': [
            {
                'field': 'process.parent.name',
                'value': 1,
            },
        ],
    }
2022-11-07 12:46:09 +04:00
..
2022-11-07 12:46:09 +04:00
2021-10-28 20:56:19 +02:00
2019-11-11 23:35:16 +01:00
2021-11-20 19:59:57 +01:00
2021-09-05 17:50:54 +02:00
2021-08-18 19:00:57 +00:00
2020-06-06 01:03:02 +02:00