mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
fixed multiple tags issue
This commit is contained in:
parent
5154460726
commit
8bec627ff1
@ -20,8 +20,6 @@ detection:
|
||||
fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: high
|
||||
|
@ -29,8 +29,6 @@ detection:
|
||||
- '*\System32\\*'
|
||||
- '*\SysWow64\\*'
|
||||
condition: selection and not filter
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
falsepositives:
|
||||
- Exotic software
|
||||
level: high
|
||||
|
Loading…
Reference in New Issue
Block a user