mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Remove backslashes in CommandLine for sticky key rule
Example command line is exactly "cmd.exe sethc.exe 211". => the detection with *\cmd.exe... would not match.
This commit is contained in:
parent
6cc1770351
commit
865d971704
@ -39,9 +39,9 @@ detection:
|
||||
ParentImage:
|
||||
- '*\winlogon.exe'
|
||||
CommandLine:
|
||||
- '*\cmd.exe sethc.exe *'
|
||||
- '*\cmd.exe utilman.exe *'
|
||||
- '*\cmd.exe osk.exe *'
|
||||
- '*\cmd.exe Magnify.exe *'
|
||||
- '*\cmd.exe Narrator.exe *'
|
||||
- '*\cmd.exe DisplaySwitch.exe *'
|
||||
- '*cmd.exe sethc.exe *'
|
||||
- '*cmd.exe utilman.exe *'
|
||||
- '*cmd.exe osk.exe *'
|
||||
- '*cmd.exe Magnify.exe *'
|
||||
- '*cmd.exe Narrator.exe *'
|
||||
- '*cmd.exe DisplaySwitch.exe *'
|
||||
|
Loading…
Reference in New Issue
Block a user