The following is a non-exhaustive list of changes between the v2.0.0 and v2.1.0 specification.
A lot of work has been done on the wording to make it easier to understand.
Some files have been renamed or moved for convenience.
There is now a workflow to check new input:
We introduced a new set of modifiers. You can check the full list of all currently supported modifiers in the Sigma Modifiers Appendix.
We introduced a new set of tags. You can check the full list of all currently supported tags in the Sigma tags Appendix.
We introduced a new generic network category. You can check the full list of sigma taxonomies in the Sigma taxonomies Appendix.
We introduced a new Metric operator in correlation
No breaking change
No breaking change