mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
fix: bugfix in BEAR activity rule
This commit is contained in:
parent
8b7f0508a7
commit
a60b53a7df
@ -28,7 +28,7 @@ detection:
|
||||
selection2:
|
||||
EventID: 1
|
||||
Image: '*\adexplorer.exe'
|
||||
CommandLine: '* -snapshot "" c:\users\*'
|
||||
CommandLine: '* -snapshot "" c:\users\\*'
|
||||
---
|
||||
logsource:
|
||||
product: windows
|
||||
@ -41,4 +41,4 @@ detection:
|
||||
selection2:
|
||||
EventID: 4688
|
||||
NewProcessName: '*\adexplorer.exe'
|
||||
ProcessCommandLine: '* -snapshot "" c:\users\*'
|
||||
ProcessCommandLine: '* -snapshot "" c:\users\\*'
|
Loading…
Reference in New Issue
Block a user