Yamato-Security / hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
GNU Affero General Public License v3.0
2.32k stars 203 forks source link

Load `windash` characters dynamically #1440

Closed YamatoSecurity closed 3 weeks ago

YamatoSecurity commented 1 month ago

Right now the windash characters (en dash, em dash, etc..) are hard coded so I want to load them dynamically from rules/config/windash_characters.txt so that we can dynamically update them.

Ref: https://github.com/Yamato-Security/hayabusa-rules/pull/744 needs to be merged first.

Details: https://www.youtube.com/watch?v=52tAmVLg1KM&t=565s