Update sysmon_stickykey_like_backdoor.yml

This commit is contained in:
yugoslavskiy 2020-11-28 18:33:21 +01:00 committed by GitHub
parent 39c2258848
commit 5196926d60
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -12,9 +12,9 @@ tags:
- attack.t1546.008
- car.2014-11-003
- car.2014-11-008
author: Florian Roth, @twjackomo, Jonhnathan Ribeiro
author: Florian Roth, @twjackomo, Jonhnathan Ribeiro, oscd.community
date: 2018/03/15
modified: 2020/09/06
modified: 2020/11/28
falsepositives:
- Unlikely
level: critical
@ -39,10 +39,8 @@ logsource:
product: windows
detection:
selection_process:
ParentImage|endswith:
- '\winlogon.exe'
Image|contains|all:
- 'cmd.exe'
ParentImage|endswith: '\winlogon.exe'
Image|endswith: '\cmd.exe'
CommandLine|contains:
- 'sethc.exe'
- 'utilman.exe'