mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
fix: bugfix in Judgement Panda rule
This commit is contained in:
parent
5935eaa572
commit
3a994d0d63
@ -57,5 +57,5 @@ detection:
|
||||
- '*copy .\1.7z \\*'
|
||||
- '*copy \\client\c$\aaaa\*'
|
||||
selection2:
|
||||
EventID: 1
|
||||
EventID: 4688
|
||||
NewProcessName: 'C:\Users\Public\7za.exe'
|
Loading…
Reference in New Issue
Block a user