diff --git a/sigma/pipelines/crowdstrike/crowdstrike.py b/sigma/pipelines/crowdstrike/crowdstrike.py index 4f4eeb4..30bbb3b 100644 --- a/sigma/pipelines/crowdstrike/crowdstrike.py +++ b/sigma/pipelines/crowdstrike/crowdstrike.py @@ -448,19 +448,6 @@ def common_processing_items(): ], field_name_condition_linking=any, ), - # ImageFileName full path handling with contains - # ProcessingItem( - # identifier="cql_imagefilename_replace_disk_name_contains", - # transformation=ReplaceStringTransformation( - # regex="^\\*[C-Z]:", replacement="*\\\\Device\\\\HarddiskVolume?\\\\" - # ), - # field_name_conditions=[ - # IncludeFieldCondition(fields=["ImageFileName"]), - # IncludeFieldCondition(fields=["TargetImageFileName"]), - # ], - # field_name_condition_linking=any, - # ), - # ImageFileName starting with colon handling ProcessingItem( identifier="cql_imagefilename_replace_disk_name", transformation=ReplaceStringTransformation(regex=":", replacement=""),