Skip to content

Commit 98736fd

Browse files
Update RootA_Specification.md
1 parent 92377ea commit 98736fd

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

RootA_Specification.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ Format: `text (max 1024 characters)`
8181

8282
Required: *mandatory*
8383

84-
Description: The name of the rule which reflects the goal and the method used in the rule
84+
Description: The name of the rule which reflects the goal and the method used in the rule.
8585

8686
Example: name: `Possible Credential Dumping using comsvcs.dll`
8787

@@ -91,7 +91,7 @@ Format: `text (max 8192 characters)`
9191

9292
Required: *optional*
9393

94-
Description: A short description of the rule that should give more context to the detection and threats that can be detected with this rule
94+
Description: A short description of the rule that should give more context to the detection and threats that can be detected with this rule.
9595

9696
Example: `details: Adversaries can use the built-in library comsvcs.dll to dump credentials on a compromised host.`
9797

@@ -207,7 +207,7 @@ YYYY-MM-DD: Actor1, Actor3, TLP:GREEN
207207

208208
Required: *optional*
209209

210-
Description: Has to include the name of the actor, TLP:key, and dates when the behavior described in the RootA rule was used by the Actor. On the contrary to indicators of compromise, which are Actor specific, behaviors are constant while Actor is a variable. If the TLP:key is not defined, it is perceived as TLP:CLEAR. The period can be defined with two dates (first and last seen) or with one date.
210+
Description: It has to include the name of the actor, TLP:key, and dates when the behavior described in the RootA rule was used by the Actor. On the contrary to indicators of compromise, which are Actor specific, behaviors are constant while Actor is a variable. If the TLP:key is not defined, it is perceived as TLP:CLEAR. The period can be defined with two dates (first and last seen) or with one date.
211211

212212
Example:
213213
```

0 commit comments

Comments
 (0)