This commit is contained in:
Jonhnathan 2020-10-15 20:24:31 -03:00 committed by GitHub
parent 86ade194a4
commit 345c3c6451
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -16,8 +16,8 @@ detection:
- 'C:\PerfLogs\\'
- 'C:\Users\Public\\'
- 'C:\Users\Default\\'
Filename|contains:
- '\\Client\\'
- '*\\Client\\'
selection2:
Filename|endswith:
- '.ps1'
- '.vbs'
@ -38,7 +38,7 @@ detection:
- '.vbe'
- '.wsf'
- '.wsh'
condition: selection
condition: selection or selection2
fields:
- Signature
- User