Update win_data_compressed.yml

This commit is contained in:
zinint 2019-10-22 14:57:53 +03:00 committed by GitHub
parent 74d1fef8b8
commit a8bd2c8e78
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -19,6 +19,9 @@ detection:
- '*\powershell.exe'
CommandLine:
- '*-Recurse | Compress-Archive*'
- '*-Recurse| Compress-Archive*'
- '*-Recurse |Compress-Archive*'
- '*-Recurse|Compress-Archive*'
condition: selection1 or selection2
fields:
- Image
@ -34,4 +37,3 @@ level: low
tags:
- attack.exfiltration
- attack.t1002