added att&ck tag

This commit is contained in:
Lurkkeli 2018-08-07 08:45:58 +02:00 committed by GitHub
parent 0bff27ec21
commit 99253763af
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -14,6 +14,10 @@ detection:
SourceImage: '*\powershell.exe'
TargetImage: '*\rundll32.exe'
condition: selection
tags:
- attack.defense_evasion
- attack.execution
- attack.t1085
falsepositives:
- Unkown
level: high