mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_susp_replace_lolbin.yml
This commit is contained in:
parent
1324bc1ad1
commit
6b2c235ab3
@ -17,8 +17,8 @@ detection:
|
|||||||
Image|endswith:
|
Image|endswith:
|
||||||
- '\replace.exe'
|
- '\replace.exe'
|
||||||
CommandLine|contains|all:
|
CommandLine|contains|all:
|
||||||
- "\\\\\\\\"
|
- '\\\'
|
||||||
- "/A"
|
- '/A'
|
||||||
condition: selection
|
condition: selection
|
||||||
falsepositives:
|
falsepositives:
|
||||||
- Legitimate use of the binary to download files from a share
|
- Legitimate use of the binary to download files from a share
|
||||||
|
Loading…
Reference in New Issue
Block a user