mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
ATT&CK tagging of MSHTA Spawning Windows Shell
This commit is contained in:
parent
76f277d5fe
commit
080892b5ab
@ -29,6 +29,10 @@ detection:
|
|||||||
fields:
|
fields:
|
||||||
- CommandLine
|
- CommandLine
|
||||||
- ParentCommandLine
|
- ParentCommandLine
|
||||||
|
tags:
|
||||||
|
- attack.defense_evasion
|
||||||
|
- attack.execution
|
||||||
|
- attack.t1170
|
||||||
falsepositives:
|
falsepositives:
|
||||||
- Printer software / driver installations
|
- Printer software / driver installations
|
||||||
level: high
|
level: high
|
||||||
|
Loading…
Reference in New Issue
Block a user