mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
added att&ck tag
This commit is contained in:
parent
0bff27ec21
commit
99253763af
@ -14,6 +14,10 @@ detection:
|
||||
SourceImage: '*\powershell.exe'
|
||||
TargetImage: '*\rundll32.exe'
|
||||
condition: selection
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.execution
|
||||
- attack.t1085
|
||||
falsepositives:
|
||||
- Unkown
|
||||
level: high
|
||||
|
Loading…
Reference in New Issue
Block a user