Open yugoslavskiy opened 4 years ago
it's not about filenames, it's about naming scheme in general. see: https://github.com/atc-project/atc-react/issues/294
Titles are also renamed, take a look here
Also following any dependencies in a given file. We just realised this with @sn0w0tter later in the process of implementing another issue
sorry, I should have added more context to it. we need to split ID from the title, and left the title human-readable, not connected to the filename itself.
title: 4688 Windows Process Creation
id: DN0001
author: '@atc_project'
description: Windows process creation log, not including command line
loggingpolicy:
- LP0001: Windows Audit Process Creation
I am not 100% sure about LP, if it should be LP0001: Windows Audit Process Creation
or just LP0001
.
This is an open question and I believe we should discuss pros/cons using Descartes square model:
well, it also makes sense to put EventID into separate field