mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update sysmon_invoke_phantom.yml
This commit is contained in:
parent
4af7f00f4a
commit
2194744803
@ -19,8 +19,8 @@ detection:
|
||||
selection:
|
||||
TargetImage|endswith: '\windows\system32\svchost.exe'
|
||||
GrantedAccess: '0x1f3fff'
|
||||
CallTrace:
|
||||
- '*unknown*'
|
||||
CallTrace|contains:
|
||||
- 'unknown'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- unknown
|
||||
|
Loading…
Reference in New Issue
Block a user