WithSecureLabs / chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Fix incorrect parsing of Sigma's Rule Collections

alexkornitzer opened this issue · comments

At the time I clearly did not read this bit of the spec properly (or at all). So that way we parse sigma into tau for Rule collections is incorrect. This results in issues (#19, #30). Correcting this should not be too difficult.