mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_dnscat2_powershell_implementation.yml
This commit is contained in:
parent
9f467f66e6
commit
a3f59d6f03
@ -19,9 +19,9 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
ParentImage|endswith: '*\powershell.exe'
|
||||
Image|endswith: '*\nslookup.exe'
|
||||
CommandLine|endswith: '*\nslookup.exe'
|
||||
ParentImage|endswith: '\powershell.exe'
|
||||
Image|endswith: '\nslookup.exe'
|
||||
CommandLine|endswith: '\nslookup.exe'
|
||||
condition: selection | count(Image) by ParentImage > 100
|
||||
fields:
|
||||
- Image
|
||||
|
Loading…
Reference in New Issue
Block a user