mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Merge pull request #1263 from Neo23x0/rule-devel
feat: cover newest emotet campaigns
This commit is contained in:
commit
6f9aeb5ea9
@ -40,6 +40,7 @@ detection:
|
||||
- '* -e* IAB*'
|
||||
- '* -e* UwB*'
|
||||
- '* -e* cwB*'
|
||||
- '*.exe -ENCOD *'
|
||||
falsepositive1:
|
||||
CommandLine: '* -ExecutionPolicy remotesigned *'
|
||||
condition: selection and not falsepositive1
|
||||
|
Loading…
Reference in New Issue
Block a user