mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update sysmon_susp_download_run_key.yml
This commit is contained in:
parent
6fc6409c7f
commit
17ade8e5f5
@ -16,11 +16,11 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
Image:
|
||||
- '*\Downloads\\*'
|
||||
- '*\Temporary Internet Files\Content.Outlook\\*'
|
||||
- '*\Local Settings\Temporary Internet Files\\*'
|
||||
TargetObject: '*\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\*'
|
||||
Image|contains:
|
||||
- '\Downloads\\'
|
||||
- '\Temporary Internet Files\Content.Outlook\\'
|
||||
- '\Local Settings\Temporary Internet Files\\'
|
||||
TargetObject|contains: '\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Software installers downloaded and used by users
|
||||
|
Loading…
Reference in New Issue
Block a user