Merge pull request #1611 from SigmaHQ/rule-devel

fix: escape character that would be interpreted as wildcard
This commit is contained in:
Florian Roth 2021-07-02 23:51:49 +02:00 committed by GitHub
commit 691cf066b9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,7 +17,7 @@ logsource:
detection:
selection:
EventID: '5145'
ShareName: '\\*\IPC$'
ShareName: '\\\*\IPC$'
RelativeTargetName: 'spoolss'
AccessMask: '0x3'
ObjectType: 'File'