Update win_netsh_port_fwd.yml

This commit is contained in:
Jonhnathan 2020-11-27 15:57:53 -03:00 committed by GitHub
parent 9171d8913c
commit 5acd8d622b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,8 +17,8 @@ logsource:
product: windows
detection:
selection:
CommandLine:
- netsh interface portproxy add v4tov4 *
CommandLine|startswith:
- 'netsh interface portproxy add v4tov4'
condition: selection
falsepositives:
- Legitimate administration