Update sysmon_susp_powershell_rundll32.yml

This commit is contained in:
Jonhnathan 2020-10-15 20:14:23 -03:00 committed by GitHub
parent 26b36086c7
commit 92aaeca075
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -12,8 +12,8 @@ logsource:
detection:
selection:
EventID: 8
SourceImage: '*\powershell.exe'
TargetImage: '*\rundll32.exe'
SourceImage|endswith: '\powershell.exe'
TargetImage|endswith: '\rundll32.exe'
condition: selection
tags:
- attack.defense_evasion