Update win_susp_net_execution.yml

This commit is contained in:
yugoslavskiy 2019-11-11 02:57:59 +03:00 committed by GitHub
parent ca819d8707
commit 24ea49a2a1
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -24,10 +24,6 @@ detection:
Image:
- '*\net.exe'
- '*\net1.exe'
filename:
OriginalFileName:
- 'net.exe'
- 'net1.exe'
cmdline:
CommandLine:
- '* group*'
@ -38,7 +34,7 @@ detection:
- '* accounts*'
- '* use*'
- '* stop *'
condition: selection or filename and cmdline
condition: selection and cmdline
fields:
- CommandLine
- ParentCommandLine