mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
ATT&CK tagging of MSHTA Spawning Windows Shell
This commit is contained in:
parent
76f277d5fe
commit
080892b5ab
@ -29,6 +29,10 @@ detection:
|
||||
fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.execution
|
||||
- attack.t1170
|
||||
falsepositives:
|
||||
- Printer software / driver installations
|
||||
level: high
|
||||
|
Loading…
Reference in New Issue
Block a user