mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update silenttrinity_stager_msbuild_activity.yml
This commit is contained in:
parent
708fe7f8fa
commit
b5e07f0a37
@ -14,13 +14,13 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
ParentImage|endswith: '\msbuild.exe'
|
||||
filter:
|
||||
DestinationPort:
|
||||
- '80'
|
||||
- '443'
|
||||
Initiated: 'true'
|
||||
filter:
|
||||
ParentImage|endswith: '\msbuild.exe'
|
||||
condition: selection and filter
|
||||
condition: selection and filter
|
||||
falsepositives:
|
||||
- unknown
|
||||
level: high
|
||||
|
Loading…
Reference in New Issue
Block a user