Skip to content

Commit

Permalink
append '4688' to new rules
Browse files Browse the repository at this point in the history
  • Loading branch information
TonyPhipps committed Sep 9, 2024
1 parent 84920ae commit 64109ee
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions Splunk/sigma/Copy-SplunkSigma-Sysmon1-to-4688.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,7 @@
$_ = $_ -replace ' IntegrityLevel=".*?"', ''
$_ = $_ -replace ' OR CurrentDirectory=".*?"', ''
$_ = $_ -replace ' CurrentDirectory=".*?"', ''
$_ = $_ -replace '^\[(.*?)\]$', '[$1 4688]'

# Return the modified line
$_
Expand Down

0 comments on commit 64109ee

Please sign in to comment.