Skip to content

Roota: crowdstrike -> sigma: "null" or "None" for windash query #13

@kostiantyntest

Description

@kostiantyntest

when crowdstrike is being translated into sigma, there is a null in selection (instead of CommandLine) which should not be as a part of detection

detection:
    language: crowdstrike-spl-query
    body: (CommandLine="-all123" OR CommandLine="/all123")

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions