Skip to content

[Rule: Tuning] Rule triggers for false positive due to broad wildcard#6205

Open
litemars wants to merge 1 commit into
elastic:mainfrom
litemars:fine_tuning_base64_decoding_activity
Open

[Rule: Tuning] Rule triggers for false positive due to broad wildcard#6205
litemars wants to merge 1 commit into
elastic:mainfrom
litemars:fine_tuning_base64_decoding_activity

Conversation

@litemars
Copy link
Copy Markdown
Contributor

Pull Request

Issue link(s):

Summary - What I changed

Feel free to close the PR if this approach doesn’t work for you. At the moment, the rule process.command_line like "*-*d*" would also trigger in cases like base64 file-data.txt, or for any filename containing both - and d.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants