Update process_creation_shadow_copies_deletion.yml

This commit is contained in:
yugoslavskiy 2019-11-14 00:50:10 +03:00 committed by GitHub
parent a1831bb503
commit 9b9f37715f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -8,16 +8,18 @@ references:
- https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/new-teslacrypt-ransomware-arrives-via-spam/
tags:
- attack.defense_evasion
- attack.impact
- attack.t1070
- attack.t1490
logsource:
category: process_creation
product: windows
detection:
selection:
NewProcessName:
- '*\powershell.exe'
- '*\wmic.exe'
- '*\vssadmin.exe'
NewProcessName|endswith:
- '\powershell.exe'
- '\wmic.exe'
- '\vssadmin.exe'
CommandLine|contains|all:
- shadow
- delete