Update win_susp_replace_lolbin.yml

This commit is contained in:
Jonhnathan 2020-10-18 23:44:18 -03:00 committed by GitHub
parent 1324bc1ad1
commit 6b2c235ab3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,8 +17,8 @@ detection:
Image|endswith:
- '\replace.exe'
CommandLine|contains|all:
- "\\\\\\\\"
- "/A"
- '\\\'
- '/A'
condition: selection
falsepositives:
- Legitimate use of the binary to download files from a share