mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_office_spawn_exe_from_users_directory.yml
This commit is contained in:
parent
58f6fd4e4f
commit
aa728e91da
@ -19,13 +19,13 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
ParentImage:
|
||||
- '*\WINWORD.EXE'
|
||||
- '*\EXCEL.EXE'
|
||||
- '*\POWERPNT.exe'
|
||||
- '*\MSPUB.exe'
|
||||
- '*\VISIO.exe'
|
||||
- '*\OUTLOOK.EXE'
|
||||
ParentImage|endswith:
|
||||
- '\WINWORD.EXE'
|
||||
- '\EXCEL.EXE'
|
||||
- '\POWERPNT.exe'
|
||||
- '\MSPUB.exe'
|
||||
- '\VISIO.exe'
|
||||
- '\OUTLOOK.EXE'
|
||||
Image:
|
||||
- 'C:\users\\*.exe'
|
||||
condition: selection
|
||||
|
Loading…
Reference in New Issue
Block a user