Update win_susp_ping_hex_ip.yml

This commit is contained in:
Jonhnathan 2020-11-28 13:01:24 -03:00 committed by GitHub
parent 1c56dc463a
commit b24945999e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -15,9 +15,9 @@ logsource:
product: windows
detection:
selection:
Image|endswith: '\ping.exe'
CommandLine|contains:
- '\ping.exe 0x'
- '\ping 0x'
- ' 0x'
condition: selection
fields:
- ParentCommandLine