SigmaHQ / sigma

Main Sigma Rule Repository
Other
7.84k stars 2.12k forks source link

Remove smart quotes from file_event_win_iphlpapi_dll_sideloading.yml #4856

Closed jeremyhagan closed 1 month ago

jeremyhagan commented 1 month ago

Summary of the Pull Request

Removed smart quotes from title of rule which were causing the payload to bomb out when sending to Microsoft Sentinel as a detection rule template

Changelog

fix: Malicious DLL File Dropped in the Teams or OneDrive Folder - Remove smart quotes

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions