fix rule due to sigmac bug?

This commit is contained in:
ecco 2020-05-18 09:39:48 -04:00
parent e89613aee0
commit 088800cd18

View File

@ -40,6 +40,8 @@ detection:
TargetFilename|contains:
- '\AppData\Local\Temp\'
- '\Windows\Temp\'
condition: selection_1 and not false_positives and (( selection_2 and selection_3 ) or ( selection_4 and selection_5 ) or selection_6)
# kind of ugly but sigmac seems not to handle double parenthesis "(("
# we shold prefer something like : selection_1 and not false_positives and ((selection_2 and selection_3) or (selection_4 and selection_5) or selection_6)
condition: (selection_1 and selection_2 and selection_3 and not false_positives) or (selection_1 and selection_4 and selection_5 and not false_positives) or (selection_1 and selection_6 and not false_positives)
falsepositives:
- Legitimate administrator or developer creating legitimate executable files in a web application folder