YARA rule help_outline
Match: PID Name Cmdline All
Filter comma-separated process IDs PIDs must be non-negative integers. Invalid: {{error.value}} Match process names with regex help_outline Match process commandline with regex help_outline
Skip memory regions:
readonly executable special shared mapped files