mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Update sysmon_susp_powershell_rundll32.yml
This commit is contained in:
parent
26b36086c7
commit
92aaeca075
@ -12,8 +12,8 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 8
|
||||
SourceImage: '*\powershell.exe'
|
||||
TargetImage: '*\rundll32.exe'
|
||||
SourceImage|endswith: '\powershell.exe'
|
||||
TargetImage|endswith: '\rundll32.exe'
|
||||
condition: selection
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
|
Loading…
Reference in New Issue
Block a user