mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Update win_data_compressed.yml
This commit is contained in:
parent
74d1fef8b8
commit
a8bd2c8e78
@ -19,6 +19,9 @@ detection:
|
||||
- '*\powershell.exe'
|
||||
CommandLine:
|
||||
- '*-Recurse | Compress-Archive*'
|
||||
- '*-Recurse| Compress-Archive*'
|
||||
- '*-Recurse |Compress-Archive*'
|
||||
- '*-Recurse|Compress-Archive*'
|
||||
condition: selection1 or selection2
|
||||
fields:
|
||||
- Image
|
||||
@ -34,4 +37,3 @@ level: low
|
||||
tags:
|
||||
- attack.exfiltration
|
||||
- attack.t1002
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user