mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update mal_azorult_reg.yml
This commit is contained in:
parent
bfb50a3d42
commit
8f4d6f802b
@ -17,8 +17,8 @@ detection:
|
||||
EventID:
|
||||
- 12
|
||||
- 13
|
||||
TargetObject|endswith:
|
||||
- 'SYSTEM\\*\services\localNETService'
|
||||
TargetObject|endswith: 'SYSTEM\
|
||||
TargetObject|endswith: '\services\localNETService'
|
||||
condition: selection
|
||||
fields:
|
||||
- Image
|
||||
|
Loading…
Reference in New Issue
Block a user