Update silenttrinity_stager_msbuild_activity.yml

This commit is contained in:
S.kiran kumar 2020-10-26 17:00:50 +05:30 committed by GitHub
parent 708fe7f8fa
commit b5e07f0a37
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -14,13 +14,13 @@ logsource:
product: windows
detection:
selection:
ParentImage|endswith: '\msbuild.exe'
filter:
DestinationPort:
- '80'
- '443'
Initiated: 'true'
filter:
ParentImage|endswith: '\msbuild.exe'
condition: selection and filter
condition: selection and filter
falsepositives:
- unknown
level: high