Closed jm404 closed 4 years ago
The preconfigured Virustotal rule has been updated to:
<rule id="100200" level="7">
<if_sid>550,553,554</if_sid>
<field name="file">\S*/virus|\S*\\virus</field>
<description>File modified or created in /virus directory.</description>
</rule>
Now it accepts WIndows and Linux paths without troubles
The rule
100200
created for Virustotal:Only matches strings with
/tmp
in it. It causes the Windows agents to fail when trying to match such rule as there is no such folder in Windows.It's required to update that folder in order to grant compatibility with Windows paths and also give a more descriptive name like
virus
for example.Tasks:
[x] Update rule regex
[x] Test Windows Agent
[x] Test Linux Agent
Best regards
Jose