Update silenttrinity_stager_msbuild_activity.yml

This commit is contained in:
S.kiran kumar 2020-10-14 13:04:49 +05:30 committed by GitHub
parent 6b25378a61
commit 2fa7ae2c1c
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,7 +17,7 @@ logsource:
detection:
selection:
EventID: 3
ParentImage|endswith: '\msbuild.exe'
ParentImage|endswith: 'msbuild.exe'
condition: selection
fields:
- ParentImage