Forum Discussion
gilly32
1 month agoBronze I
Wizard Spider DFIR: Ep.9 – Sigma
The question I'm stuck on is : Modify the rule file "file_event_win_macro_file.yml" to also include ".docm" file types. Convert this rule using Sigmac and use the output within Elastic. How many pot...
SamDickison
Community Manager
1 month agoHey gilly32, I know a few people who have completed this lab who might be able to give a help: Carlossus GusC neeemu purplemoon CyberSharpe. Otherwise I'll get one of the team to have a look for you.