mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Improved shell spawning rule
This commit is contained in:
parent
ef7fb4cff1
commit
52d405bb1b
@ -24,6 +24,7 @@ detection:
|
||||
- '*\nslookup.exe'
|
||||
- '*\certutil.exe'
|
||||
- '*\bitsadmin.exe'
|
||||
- '*\mshta.exe'
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
Loading…
Reference in New Issue
Block a user