mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
6 lines
254 B
YAML
6 lines
254 B
YAML
definition: lookup update=true ransomware_extensions_lookup Extensions AS file_extension
|
|
OUTPUT Name | search Name !=False
|
|
description: This macro limits the output to files that have extensions associated
|
|
with ransomware
|
|
name: ransomware_extensions
|