Update sysmon_quarkspw_filedump.yml

This commit is contained in:
Jonhnathan 2020-10-27 22:02:47 -03:00 committed by GitHub
parent dde5b46726
commit 182b12614b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -18,7 +18,9 @@ logsource:
detection:
selection:
# Sysmon: File Creation (ID 11)
TargetFilename|contains: '\AppData\Local\Temp\SAM-*.dmp'
TargetFilename|contains|all:
- '\AppData\Local\Temp\SAM-'
- '.dmp'
condition: selection
falsepositives:
- Unknown