mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Completed requested changes
selection2: Image|endswith:
This commit is contained in:
parent
ff08de6d20
commit
918bcfbf8a
@ -22,7 +22,7 @@ detection:
|
||||
EventType: WMIExecution
|
||||
WMIcommand|contains: 'Win32_Process\:\:Create'
|
||||
selection2:
|
||||
- Image|endswith:
|
||||
Image|endswith:
|
||||
- '\winword.exe'
|
||||
- '\excel.exe'
|
||||
- '\powerpnt.exe'
|
||||
|
Loading…
Reference in New Issue
Block a user