mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
rule: modified the default
This commit is contained in:
parent
312311494d
commit
0e2284a176
@ -14,14 +14,14 @@ detection:
|
|||||||
Image: '*\chcp.com'
|
Image: '*\chcp.com'
|
||||||
CommandLine:
|
CommandLine:
|
||||||
- '* 936' # Chinese
|
- '* 936' # Chinese
|
||||||
- '* 1256' # Arabic
|
# - '* 1256' # Arabic
|
||||||
- '* 1258' # Vietnamese
|
- '* 1258' # Vietnamese
|
||||||
- '* 855' # Russian
|
# - '* 855' # Russian
|
||||||
- '* 866' # Russian
|
# - '* 866' # Russian
|
||||||
- '* 864' # Arabic
|
# - '* 864' # Arabic
|
||||||
condition: selection
|
condition: selection
|
||||||
fields:
|
fields:
|
||||||
- ParentCommandLine
|
- ParentCommandLine
|
||||||
falsepositives:
|
falsepositives:
|
||||||
- Administrative activity of foreign staff
|
- "Administrative activity (adjust code pages according to your organisation's region)"
|
||||||
level: medium
|
level: medium
|
||||||
|
Loading…
Reference in New Issue
Block a user