Forum Discussion
gilly32
5 months agoBronze I
Wizard Spider DFIR: Ep.9 – Sigma
The question I'm stuck on is : Modify the rule file "file_event_win_macro_file.yml" to also include ".docm" file types. Convert this rule using Sigmac and use the output within Elastic. How many pot...
SamDickison
Community Manager
5 months agoHey gilly32, I know a few people who have completed this lab who might be able to give a help: Carlossus GusC neeemu purplemoon CyberSharpe. Otherwise I'll get one of the team to have a look for you.