rabbitstack / fibratus

Adversary tradecraft detection, protection, and hunting
https://www.fibratus.io
Other
2.21k stars 189 forks source link

refactor(filter,rules): Deprecate pe.ps.child.file.name field #341

Closed rabbitstack closed 3 weeks ago

rabbitstack commented 3 weeks ago

What is the purpose of this PR / why it is needed?

Introduce a new filter field ps.child.pe.file.name that is uniform with the other ps.child.* fields.

What type of change does this PR introduce?

Any specific area of the project related to this PR?

Special notes for the reviewer:

Does this PR introduce a user-facing change?

Yes. The fields documentation needs to be updated to express the usage preference of the new filter field.