Skip to content

Commit 0ef1cb1

Browse files
Samirbousgithub-actions[bot]
authored andcommitted
[New Rules] C2 via BITS and CertReq (#2466)
* Create command_and_control_certreq_postdata.toml * Update command_and_control_certreq_postdata.toml * Update command_and_control_certreq_postdata.toml * Create command_and_control_ingress_transfer_bits.toml * Update non-ecs-schema.json * Update command_and_control_certreq_postdata.toml * Update command_and_control_ingress_transfer_bits.toml * Update rules/windows/command_and_control_certreq_postdata.toml Co-authored-by: Terrance DeJesus <[email protected]> --------- Co-authored-by: Terrance DeJesus <[email protected]> (cherry picked from commit b8dcc6a)
1 parent cb283be commit 0ef1cb1

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

detection_rules/etc/non-ecs-schema.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -69,8 +69,9 @@
6969
"file.Ext.header_bytes": "keyword",
7070
"file.Ext.entropy": "long",
7171
"file.size": "long",
72+
"file.Ext.original.name": "keyword",
7273
"dll.Ext.relative_file_creation_time": "double",
73-
"dll.Ext.relative_file_name_modify_time": "double" ,
74+
"dll.Ext.relative_file_name_modify_time": "double",
7475
"process.Ext.relative_file_name_modify_time": "double",
7576
"process.Ext.relative_file_creation_time": "double"
7677
},

0 commit comments

Comments
 (0)