rule logic fix

This commit is contained in:
Mikhail Larin 2020-10-21 18:32:02 +03:00
parent e0e81b5c25
commit 13d84ac27b

View File

@ -13,8 +13,9 @@ logsource:
category: process_creation
detection:
selection1:
CommandLine|contains|all:
- 'grep'
ProcessName|endswith:
- '/grep'
CommandLine|contains:
- 'password'
selection2:
CommandLine|contains: 'laZagne'