mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
rule: minor improvement to susp ps enc cmd
This commit is contained in:
parent
03d45d57de
commit
7bef822da7
@ -22,6 +22,7 @@ detection:
|
||||
- '* -e JAB*'
|
||||
- '* -e JAB*'
|
||||
- '* -enc JAB*'
|
||||
- '* -enco JAB*'
|
||||
- '* -encodedcommand JAB*'
|
||||
- '* BA^J e-'
|
||||
- '* -e SUVYI*'
|
||||
|
Loading…
Reference in New Issue
Block a user