mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
rule logic fix
This commit is contained in:
parent
e0e81b5c25
commit
13d84ac27b
@ -13,8 +13,9 @@ logsource:
|
||||
category: process_creation
|
||||
detection:
|
||||
selection1:
|
||||
CommandLine|contains|all:
|
||||
- 'grep'
|
||||
ProcessName|endswith:
|
||||
- '/grep'
|
||||
CommandLine|contains:
|
||||
- 'password'
|
||||
selection2:
|
||||
CommandLine|contains: 'laZagne'
|
||||
|
Loading…
Reference in New Issue
Block a user