mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Rule: CertUtil UA
https://twitter.com/ItsReallyNick/status/1047151134501216258
This commit is contained in:
parent
4eeb07a736
commit
54678fcb36
@ -20,6 +20,7 @@ detection:
|
||||
- ' Mozilla/*' # leading space
|
||||
- 'Mozila/*' # single 'l'
|
||||
- '_'
|
||||
- 'CertUtil URL Agent' # https://twitter.com/stvemillertime/status/985150675527974912
|
||||
falsepositives:
|
||||
UserAgent:
|
||||
- 'Mozilla/3.0 * Acrobat *' # Acrobat with linked content
|
||||
|
Loading…
Reference in New Issue
Block a user