mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update win_susp_replace_lolbin.yml
This commit is contained in:
parent
1324bc1ad1
commit
6b2c235ab3
@ -17,8 +17,8 @@ detection:
|
||||
Image|endswith:
|
||||
- '\replace.exe'
|
||||
CommandLine|contains|all:
|
||||
- "\\\\\\\\"
|
||||
- "/A"
|
||||
- '\\\'
|
||||
- '/A'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Legitimate use of the binary to download files from a share
|
||||
|
Loading…
Reference in New Issue
Block a user