mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
zeek, swap path
and name
This commit is contained in:
parent
4446c4cd4e
commit
2fc8d513d6
@ -16,8 +16,8 @@ logsource:
|
||||
service: smb_files
|
||||
detection:
|
||||
selection:
|
||||
name: \\*\IPC$
|
||||
path: atsvc
|
||||
path: \\*\IPC$
|
||||
name: atsvc
|
||||
#Accesses: '*WriteData*'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
|
@ -13,8 +13,8 @@ logsource:
|
||||
service: smb_files
|
||||
detection:
|
||||
selection:
|
||||
name: '\\*ADMIN$'
|
||||
path: '*SYSTEM32\\*.tmp'
|
||||
path: '\\*ADMIN$'
|
||||
name: '*SYSTEM32\\*.tmp'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- 'unknown'
|
||||
|
@ -14,10 +14,10 @@ logsource:
|
||||
service: smb_files
|
||||
detection:
|
||||
selection1:
|
||||
name: \\*\IPC$
|
||||
path: \\*\IPC$
|
||||
selection2:
|
||||
name: \\*\IPC$
|
||||
path:
|
||||
path: \\*\IPC$
|
||||
name:
|
||||
- 'atsvc'
|
||||
- 'samr'
|
||||
- 'lsarpc'
|
||||
|
@ -13,8 +13,8 @@ logsource:
|
||||
service: smb_files
|
||||
detection:
|
||||
selection1:
|
||||
name: \\*\IPC$
|
||||
path:
|
||||
path: \\*\IPC$
|
||||
name:
|
||||
- '*-stdin'
|
||||
- '*-stdout'
|
||||
- '*-stderr'
|
||||
|
@ -11,7 +11,7 @@ logsource:
|
||||
service: smb_files
|
||||
detection:
|
||||
selection:
|
||||
path:
|
||||
name:
|
||||
- '*.pst'
|
||||
- '*.ost'
|
||||
- '*.msg'
|
||||
|
@ -13,7 +13,7 @@ logsource:
|
||||
service: smb_files
|
||||
detection:
|
||||
selection:
|
||||
path:
|
||||
name:
|
||||
- '\mimidrv'
|
||||
- '\lsass'
|
||||
- '\windows\minidump\'
|
||||
|
Loading…
Reference in New Issue
Block a user