mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update win_apt_zxshell.yml
This commit is contained in:
parent
0489a50bd0
commit
b1de627e94
@ -17,7 +17,7 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
CommandLine|contains:
|
||||
- 'rundll32.exe *,zxFunction*'
|
||||
- 'rundll32.exe *,RemoteDiskXXXXX'
|
||||
condition: selection
|
||||
|
Loading…
Reference in New Issue
Block a user