A rule’s mandatory sections and their values include the items below. For mandatory sections relevant to the class section that is selected, see the class section under Windows custom signatures.The keywords Include and Exclude are used for all sections except for Id, level, and directives. Include means that the section works on the value indicated, and Exclude means that the section works on all values except the one indicated.
|
You can create a signature with multiple rules by simply adding one rule after another. Keep in mind that each rule in the same signature must have the same value for its id and level sections.
|