YARA rule help_outline
Match:
PID Name Cmdline All
Filter comma-separated process IDs PIDs must be non-negative integers. Invalid: {{error.value}} Match process names with regex help_outline Match process commandline with regex help_outline
Match context capture window Context window must be a non-negative integers. Invalid: {{controls.contextWindow.errors?.['invalidIntegerEntry']}}
Skip memory regions:
readonly executable special shared mapped files