Update win_susp_replace_lolbin.yml

This commit is contained in:
Jonhnathan 2020-10-18 23:44:18 -03:00 committed by GitHub
parent 1324bc1ad1
commit 6b2c235ab3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,8 +17,8 @@ detection:
Image|endswith: Image|endswith:
- '\replace.exe' - '\replace.exe'
CommandLine|contains|all: CommandLine|contains|all:
- "\\\\\\\\" - '\\\'
- "/A" - '/A'
condition: selection condition: selection
falsepositives: falsepositives:
- Legitimate use of the binary to download files from a share - Legitimate use of the binary to download files from a share