Update win_mal_ryuk.yml

This commit is contained in:
Jonhnathan 2020-10-27 22:47:41 -03:00 committed by GitHub
parent 514f9ccd28
commit 266109f3d8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -11,8 +11,9 @@ logsource:
product: windows
detection:
selection:
ProcessName|contains:
- 'net.exe'
ProcessName|endswith:
- '\net.exe'
- '\net1.exe'
CommandLine|contains|all:
- 'stop'
CommandLine|contains: