Files
splunk-security_content/lookups/is_net_windows_file.yml
2022-01-20 14:34:04 -07:00

6 lines
383 B
YAML

default_match: 'false'
description: A full baseline of executable files in \Windows\, including sub-directories from Server 2016 and Windows 11. Certain .net binaries may not have been captured due to different Windows SDK's or developer utilities not installed during baseline.
filename: is_net_windows_file.csv
min_matches: 1
name: is_net_windows_file
case_sensitive_match: 'false'