Improved shell spawning rule

This commit is contained in:
Florian Roth 2018-04-11 20:09:28 +02:00
parent ef7fb4cff1
commit 52d405bb1b

View File

@ -24,6 +24,7 @@ detection:
- '*\nslookup.exe'
- '*\certutil.exe'
- '*\bitsadmin.exe'
- '*\mshta.exe'
condition: selection
fields:
- CommandLine