Files
splunk-security_content/macros/ransomware_notes.yml
2019-10-16 16:38:05 +02:00

6 lines
279 B
YAML

definition: lookup ransomware_notes_lookup ransomware_notes as file_name OUTPUT status
as "Known Ransomware Notes" | search "Known Ransomware Notes"=True
description: This macro limits the output to files that have been identified as a
ransomware note
name: ransomware_notes