rabbitstack / fibratus

Adversary tradecraft detection, protection, and hunting
https://www.fibratus.io
Other
2.21k stars 189 forks source link

chore(alertsenders): Add alert identifier #339

Closed rabbitstack closed 3 weeks ago

rabbitstack commented 3 weeks ago

What is the purpose of this PR / why it is needed?

The alert identifier maps the alert to their respective runtime behavior or YARA rules.

What type of change does this PR introduce?

Any specific area of the project related to this PR?

Special notes for the reviewer:

Does this PR introduce a user-facing change?