Update default queries

This commit is contained in:
DefensiveDepth
2024-04-19 16:33:35 -04:00
parent 6c6647629c
commit a237ef5d96
2 changed files with 3 additions and 5 deletions

View File

@@ -43,6 +43,7 @@ def compile_yara_rules(rules_dir):
"event.dataset": "soc.detections",
"log.level": "error",
"error.message": error_message,
"error.analysis": "syntax error",
"detection_type": "yara",
"rule.uuid": rule_id,
"error.type": "runtime_status"