Merge pull request #1263 from Neo23x0/rule-devel

feat: cover newest emotet campaigns
This commit is contained in:
Florian Roth 2020-10-24 00:02:39 +02:00 committed by GitHub
commit 6f9aeb5ea9
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -40,6 +40,7 @@ detection:
- '* -e* IAB*'
- '* -e* UwB*'
- '* -e* cwB*'
- '*.exe -ENCOD *'
falsepositive1:
CommandLine: '* -ExecutionPolicy remotesigned *'
condition: selection and not falsepositive1