Skip to content

invalid token '*' in certain condition strings #20

@veramine

Description

@veramine

Could not parse this one:

detection:
  selection1:
    CommandLine|contains: 'setup0.exe -p'
  selection2a:
    CommandLine|contains: 'setup.exe'
  selection2b:
    CommandLine|endswith:
      - '-x:0'
      - '-x:1'
      - '-x:2'
  condition: selection1 or all of selection2*

invalid token '*'

https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_apt_winnti_pipemon.yml

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions