chronicle / detection-rules

Collection of YARA-L 2.0 sample rules for the Chronicle Detection API
https://chronicle.security
Apache License 2.0
290 stars 69 forks source link

Fix UDM field #1

Closed daabr closed 3 years ago

daabr commented 3 years ago

$e1.principal.target.file.sha256 --> $e1.target.file.sha256