Update win_dns_exfiltration_tools_execution.yml

This commit is contained in:
Jonhnathan 2020-10-15 17:49:18 -03:00 committed by GitHub
parent 1f7f0956af
commit 9f467f66e6
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -19,7 +19,7 @@ logsource:
product: windows
detection:
selection:
- Image|endswith: '*\iodine.exe'
- Image|endswith: '\iodine.exe'
- Image|contains: '\dnscat2'
condition: selection
falsepositives: