Feature/sigmarule wildcard regex caseinsensitive#119 (#123)
* under constructing * underconstructing * fix rule file for SIGMA rule. * wildcard case insensetive. * refactor * Update src/detections/rule.rs add test triple backshash Co-authored-by: itiB <is0312vx@ed.ritsumei.ac.jp> * remove unnecessary if statement Co-authored-by: itiB <is0312vx@ed.ritsumei.ac.jp>
This commit is contained in:
@@ -8,7 +8,7 @@ detection:
|
||||
selection:
|
||||
Channel: Windows PowerShell
|
||||
EventID: 400
|
||||
EventData: '[\s\S]*EngineVersion=2.0[\s\S]*'
|
||||
EventData|re: '[\s\S]*EngineVersion=2\.0[\s\S]*'
|
||||
falsepositives:
|
||||
- unknown
|
||||
level: medium
|
||||
|
||||
Reference in New Issue
Block a user