mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
fix: single list item issue
This commit is contained in:
parent
505140d273
commit
1aac21ba79
@ -15,7 +15,7 @@ logsource:
|
|||||||
category: wmi_event
|
category: wmi_event
|
||||||
detection:
|
detection:
|
||||||
selection_destination:
|
selection_destination:
|
||||||
- Destination|base64offset|contains:
|
Destination|base64offset|contains:
|
||||||
- 'WriteProcessMemory'
|
- 'WriteProcessMemory'
|
||||||
- 'This program cannot be run in DOS mode'
|
- 'This program cannot be run in DOS mode'
|
||||||
- 'This program must be run under Win32'
|
- 'This program must be run under Win32'
|
||||||
|
Loading…
Reference in New Issue
Block a user