Stages and Predicates
Stage 1: all of selection_metadata
or:
Description: 'GnuPG’s OpenPGP tool'
Image|endswith: '\gpg.exe'
Image|endswith: '\gpg2.exe'
Stage 2: all of selection_cli
CommandLine|contains: ' -c '
CommandLine|contains: passphrase
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|
CommandLine | match | -c corpus 11 (sigma 11)passphrase corpus 2 (sigma 2)
|
Description | eq | GnuPG’s OpenPGP tool corpus 4 (sigma 4)
|
Image | ends_with | \gpg.exe corpus 5 (sigma 5)\gpg2.exe corpus 5 (sigma 5)
|