Skip to content

Commit a8a42d4

Browse files
committed
Minor fix
1 parent 93462a6 commit a8a42d4

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

docs/security/threat-intelligence/threat-intelligence-mapping.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ Following are the normalized values for CrowdStrike:
2929

3030
All other fields will be kept in the `fields{}` object.
3131

32-
*The value `malicious-activity` is used for the `threatType` if the regex matches: `name=threattype\/(clickfraud|commodity|pointofsale|randomware|targeted|targetedcrimeware)`. The value `anomalous-activity` is used if the regex matches `name=threattype\/`, and the value `unknown` is used if nothing matches.
32+
*The value `malicious-activity` is used for the `threatType` if the regex matches: `name=threattype\/(clickfraud|commodity|pointofsale|ransomware|targeted|targetedcrimeware)`. The value `anomalous-activity` is used if the regex matches `name=threattype\/`, and the value `unknown` is used if nothing matches.
3333

3434
### Type mapping for CrowdStrike
3535

0 commit comments

Comments
 (0)