diff --git a/data/rules/maxmind.yml b/data/rules/maxmind.yml index 0433716..fa7cee8 100644 --- a/data/rules/maxmind.yml +++ b/data/rules/maxmind.yml @@ -41,18 +41,15 @@ rules: (?:account|user) (?:.|[\n\r]){0,10}? (?:id|number) - (?:.|[\n\r]){0,10}? - [:=\s]+ - \s* - ["']? + (?:.|[\n\r]){0,16}? \b ( \d{4,8} ) \b - ["']? min_entropy: 2.0 - confidence: low + confidence: medium + visible: false examples: - MAXMIND_ACCOUNT_ID=123456 - AccountID 988765