Edited win_susp_pcwutl

This commit is contained in:
Yuliya Fomina 2020-10-05 14:00:21 +03:00
parent 39f955d24d
commit 815aa3c719

View File

@ -18,9 +18,7 @@ logsource:
detection:
selection:
Image|endswith: '\rundll32.exe'
CommandLine|contains|all:
- 'pcwutl'
- 'LaunchApplication'
CommandLine|contains: 'pcwutl*LaunchApplication'
condition: selection
level: medium
falsepositives: