Remove Additional backslash

This commit is contained in:
Jonhnathan 2020-11-27 15:45:08 -03:00 committed by GitHub
parent 0bf996d66e
commit 9171d8913c
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -29,26 +29,26 @@ detection:
susp_image:
CommandLine|contains:
- '%TEMP%'
- ':\RECYCLER\\'
- 'C:\$Recycle.bin\\'
- ':\SystemVolumeInformation\\'
- 'C:\\Windows\\Tasks\\'
- 'C:\\Windows\\debug\\'
- 'C:\\Windows\\fonts\\'
- 'C:\\Windows\\help\\'
- 'C:\\Windows\\drivers\\'
- 'C:\\Windows\\addins\\'
- 'C:\\Windows\\cursors\\'
- 'C:\\Windows\\system32\tasks\\'
- 'C:\Windows\Temp\\'
- 'C:\Temp\\'
- 'C:\Users\Public\\'
- '%Public%\\'
- 'C:\Users\Default\\'
- 'C:\Users\Desktop\\'
- '\Downloads\\'
- '\Temporary Internet Files\Content.Outlook\\'
- '\Local Settings\Temporary Internet Files\\'
- ':\RECYCLER\'
- 'C:\$Recycle.bin\'
- ':\SystemVolumeInformation\'
- 'C:\\Windows\\Tasks\'
- 'C:\\Windows\\debug\'
- 'C:\\Windows\\fonts\'
- 'C:\\Windows\\help\'
- 'C:\\Windows\\drivers\'
- 'C:\\Windows\\addins\'
- 'C:\\Windows\\cursors\'
- 'C:\\Windows\\system32\tasks\'
- 'C:\Windows\Temp\'
- 'C:\Temp\'
- 'C:\Users\Public\'
- '%Public%\'
- 'C:\Users\Default\'
- 'C:\Users\Desktop\'
- '\Downloads\'
- '\Temporary Internet Files\Content.Outlook\'
- '\Local Settings\Temporary Internet Files\'
condition: (selection1 or selection2) and susp_image
falsepositives:
- Legitimate administration