mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
rule: modified the default
This commit is contained in:
parent
312311494d
commit
0e2284a176
@ -14,14 +14,14 @@ detection:
|
||||
Image: '*\chcp.com'
|
||||
CommandLine:
|
||||
- '* 936' # Chinese
|
||||
- '* 1256' # Arabic
|
||||
# - '* 1256' # Arabic
|
||||
- '* 1258' # Vietnamese
|
||||
- '* 855' # Russian
|
||||
- '* 866' # Russian
|
||||
- '* 864' # Arabic
|
||||
# - '* 855' # Russian
|
||||
# - '* 866' # Russian
|
||||
# - '* 864' # Arabic
|
||||
condition: selection
|
||||
fields:
|
||||
- ParentCommandLine
|
||||
falsepositives:
|
||||
- Administrative activity of foreign staff
|
||||
- "Administrative activity (adjust code pages according to your organisation's region)"
|
||||
level: medium
|
||||
|
Loading…
Reference in New Issue
Block a user