Update win_invoke_obfuscation_via_use_mhsta.yml

This commit is contained in:
Nikita Nazarov 2020-10-09 16:30:18 +03:00 committed by GitHub
parent 60997b0243
commit 4205bb2227
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -16,7 +16,7 @@ logsource:
product: windows
detection:
selection:
- CommandLine|re: '(?i).*downloadstring&&.*mshta.*powershell.*\(window.close\).*"'
- CommandLine|re: '(?i).*(set).*(&&).*(mshta).*(vbscript:createobject).*(\.run).*\(window\.close\).*"'
condition: selection
falsepositives:
- Unknown