Update win_office_spawn_exe_from_users_directory.yml

This commit is contained in:
Jonhnathan 2020-11-27 16:04:55 -03:00 committed by GitHub
parent f6aaa957ff
commit bf5aa947e3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -26,8 +26,9 @@ detection:
- '\MSPUB.exe'
- '\VISIO.exe'
- '\OUTLOOK.EXE'
Image:
- 'C:\users\\*.exe'
Image|contains|all:
- 'C:\users\'
- '.exe'
condition: selection
fields:
- CommandLine