rule: the actual changes to hwp rule

This commit is contained in:
Florian Roth 2019-10-24 15:35:13 +02:00
parent 86c1b4ae4b
commit a5ec6722a1

View File

@ -22,9 +22,9 @@ logsource:
product: windows
detection:
selection:
CommandLine: '*\rundll32.exe *,#*'
ParentImage: '*\Hwp.exe'
Image: '*\gbb.exe'
condition: selection
falsepositives:
- False positives depend on scripts and administrative tools used in the monitored environment
- Windows contol panel elements have been identified as source (mmc)
- Unknown
level: high