Update win_hack_koadic.yml

This commit is contained in:
Jonhnathan 2020-10-15 17:53:44 -03:00 committed by GitHub
parent f44eb6345c
commit 0b52f14639
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -21,8 +21,8 @@ logsource:
product: windows
detection:
selection1:
CommandLine:
- '*cmd.exe* /q /c chcp *'
CommandLine|contains:
- 'cmd.exe* /q /c chcp '
condition: selection1
fields:
- CommandLine