Merge pull request #1611 from SigmaHQ/rule-devel

fix: escape character that would be interpreted as wildcard
This commit is contained in:
Florian Roth 2021-07-02 23:51:49 +02:00 committed by GitHub
commit 691cf066b9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,7 +17,7 @@ logsource:
detection: detection:
selection: selection:
EventID: '5145' EventID: '5145'
ShareName: '\\*\IPC$' ShareName: '\\\*\IPC$'
RelativeTargetName: 'spoolss' RelativeTargetName: 'spoolss'
AccessMask: '0x3' AccessMask: '0x3'
ObjectType: 'File' ObjectType: 'File'