mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update win_mal_ryuk.yml
This commit is contained in:
parent
514f9ccd28
commit
266109f3d8
@ -11,8 +11,9 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
ProcessName|contains:
|
||||
- 'net.exe'
|
||||
ProcessName|endswith:
|
||||
- '\net.exe'
|
||||
- '\net1.exe'
|
||||
CommandLine|contains|all:
|
||||
- 'stop'
|
||||
CommandLine|contains:
|
||||
|
Loading…
Reference in New Issue
Block a user