@@ -35,7 +35,7 @@ <h5 class="mb-0 text-white"><i class="fas fa-info-circle me-2"></i> Search Help<
3535 </ thead >
3636 < tbody >
3737 <!-- General / Metadata -->
38- < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-dark "> General & Metadata</ th > </ tr >
38+ < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-white "> General & Metadata</ th > </ tr >
3939 < tr > < td class ="text-center "> < code > id:</ code > </ td > < td > Task ID (e.g., < code > id:1</ code > )</ td > </ tr >
4040 < tr > < td class ="text-center "> < code > ids:</ code > </ td > < td > List of Task IDs (e.g., < code > ids:1,2,3</ code > )</ td > </ tr >
4141 < tr > < td class ="text-center "> < code > options:</ code > </ td > < td > Task options (e.g., < code > options:function=DllMain</ code > )</ td > </ tr >
@@ -48,7 +48,7 @@ <h5 class="mb-0 text-white"><i class="fas fa-info-circle me-2"></i> Search Help<
4848 < tr > < td class ="text-center "> < code > configs:</ code > </ td > < td > Extracted config value</ td > </ tr >
4949
5050 <!-- File Analysis -->
51- < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-dark "> File Properties & Static Analysis</ th > </ tr >
51+ < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-white "> File Properties & Static Analysis</ th > </ tr >
5252 < tr > < td class ="text-center "> < code > target_sha256:</ code > </ td > < td > Target file SHA256</ td > </ tr >
5353 < tr > < td class ="text-center "> < code > name:</ code > </ td > < td > File name pattern</ td > </ tr >
5454 < tr > < td class ="text-center "> < code > type:</ code > </ td > < td > File type/format</ td > </ tr >
@@ -68,7 +68,7 @@ <h5 class="mb-0 text-white"><i class="fas fa-info-circle me-2"></i> Search Help<
6868 < tr > < td class ="text-center "> < code > procmemyara:</ code > </ td > < td > Yara Rule Name (memory dumps)</ td > </ tr >
6969
7070 <!-- Network Analysis -->
71- < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-dark "> Network Analysis</ th > </ tr >
71+ < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-white "> Network Analysis</ th > </ tr >
7272 < tr > < td class ="text-center "> < code > ip:</ code > </ td > < td > Contacted IP address</ td > </ tr >
7373 < tr > < td class ="text-center "> < code > domain:</ code > </ td > < td > Contacted domain</ td > </ tr >
7474 < tr > < td class ="text-center "> < code > url:</ code > </ td > < td > Contacted URL or URL Analysis Target</ td > </ tr >
@@ -93,7 +93,7 @@ <h5 class="mb-0 text-white"><i class="fas fa-info-circle me-2"></i> Search Help<
9393 < tr > < td class ="text-center "> < code > surihttp:</ code > </ td > < td > Suricata HTTP Generic</ td > </ tr >
9494
9595 <!-- Behavioral / Dynamic Analysis -->
96- < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-dark "> Behavior & Execution</ th > </ tr >
96+ < tr class ="table-secondary "> < th colspan ="2 " class ="text-center text-white "> Behavior & Execution</ th > </ tr >
9797 < tr > < td class ="text-center "> < code > file:</ code > </ td > < td > Open files matching pattern</ td > </ tr >
9898 < tr > < td class ="text-center "> < code > command:</ code > </ td > < td > Executed commands matching pattern</ td > </ tr >
9999 < tr > < td class ="text-center "> < code > resolvedapi:</ code > </ td > < td > APIs resolved at runtime</ td > </ tr >
0 commit comments