Update win_apt_zxshell.yml

This commit is contained in:
Florian Roth 2020-07-16 08:47:24 +02:00 committed by GitHub
parent 0489a50bd0
commit b1de627e94
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,7 +17,7 @@ logsource:
product: windows
detection:
selection:
CommandLine:
CommandLine|contains:
- 'rundll32.exe *,zxFunction*'
- 'rundll32.exe *,RemoteDiskXXXXX'
condition: selection