diff --git a/CHANGES b/CHANGES index c6cc7fd518..261c88494e 100644 --- a/CHANGES +++ b/CHANGES @@ -1,4 +1,8 @@ +2.6-536 | 2019-06-28 12:10:55 -0700 + + * Add Windows Minidump file signature (Alexander Bolshakov) + 2.6-534 | 2019-06-28 11:48:41 -0700 * Change notices to be processed on worker. (Johanna Amann, Corelight) diff --git a/VERSION b/VERSION index f81a0a1c61..5afbf50255 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -2.6-534 +2.6-536 diff --git a/scripts/base/frameworks/files/magic/general.sig b/scripts/base/frameworks/files/magic/general.sig index 23b1c1d074..6494a2ca54 100644 --- a/scripts/base/frameworks/files/magic/general.sig +++ b/scripts/base/frameworks/files/magic/general.sig @@ -414,3 +414,9 @@ signature file-vim-tmp { file-mime "application/x-vim-tmp", 100 file-magic /^b0VIM/ } + +# Windows Minidump +signature file-windows-minidump { + file-mime "application/x-windows-minidump", 50 + file-magic /^MDMP/ +}