Actions
Optimization #2530
closedPrint matching rule SID in filestore meta file
Effort:
low
Difficulty:
low
Label:
Description
If a file gets stored because of a matching rule with the "filestore;" keyword, it would be helpful to print the SID of the matching rule in the "file.meta"-file. If you have an automated analysis of the extracted / stored files you often use "noalert;"-rules to only store the files and don't generate an alert additionally to it. But sometimes it could be useful to make the conclusion SID -> file afterwards.
Actions