Hi,
Does anyone have any experience with creating a YARA-L rule that looks for a particular event such as a vulnerability detected on a particular host but if that same vulnerability is detected in an event on the same host again within 24 hours, then to ignore and not generate an alert. So only just alert on unique events over a 24 hour period.
Thanks

