From a04b63662c3e0fc8082fe7d3dd83042e65fb083b Mon Sep 17 00:00:00 2001 From: DustInDark Date: Tue, 22 Feb 2022 23:17:48 +0900 Subject: [PATCH] Bugfix/fixed alias to no detect rename binary rule (#406) * added OriginalFileName alias #405 * removed not exist tag in sigma rule(OriginalFilename) * fixed typo --- config/eventkey_alias.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/eventkey_alias.txt b/config/eventkey_alias.txt index 2a5e4d7f..68b4e57b 100644 --- a/config/eventkey_alias.txt +++ b/config/eventkey_alias.txt @@ -95,7 +95,7 @@ ObjectType,Event.EventData.ObjectType ObjectValueName,Event.EventData.ObjectValueName OldUacValue,Event.EventData.OldUacValue Origin,Event.EventData.Origin -OriginalFilename,Event.EventData.OriginalFileName +OriginalFileName,Event.EventData.OriginalFileName param1,Event.EventData.param1 param2,Event.EventData.param2 param3,Event.EventData.param3