mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update win_mal_flowcloud.yml
This commit is contained in:
parent
ef646e74d8
commit
8d44548a2c
@ -21,7 +21,8 @@ detection:
|
||||
- 'HKLM\HARDWARE\{804423C2-F490-4ac3-BFA5-13DEDE63A71A}'
|
||||
- 'HKLM\HARDWARE\{A5124AF5-DF23-49bf-B0ED-A18ED3DEA027}'
|
||||
- 'HKLM\HARDWARE\{2DB80286-1784-48b5-A751-B6ED1F490303}'
|
||||
- 'HKLM\SYSTEM\Setup\PrintResponsor\\*'
|
||||
TargetObject|startswith:
|
||||
- 'HKLM\SYSTEM\Setup\PrintResponsor\\'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
|
Loading…
Reference in New Issue
Block a user