mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Update win_office_spawn_exe_from_users_directory.yml
This commit is contained in:
parent
f6aaa957ff
commit
bf5aa947e3
@ -26,8 +26,9 @@ detection:
|
||||
- '\MSPUB.exe'
|
||||
- '\VISIO.exe'
|
||||
- '\OUTLOOK.EXE'
|
||||
Image:
|
||||
- 'C:\users\\*.exe'
|
||||
Image|contains|all:
|
||||
- 'C:\users\'
|
||||
- '.exe'
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
Loading…
Reference in New Issue
Block a user