mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Update win_nltest_recon.yml
change "startswith" to "contains"
This commit is contained in:
parent
df829f0d45
commit
bf9ac21ebc
@ -26,7 +26,7 @@ detection:
|
||||
- '/server'
|
||||
- '/query'
|
||||
selection_recon2:
|
||||
CommandLine|startswith:
|
||||
CommandLine|contains:
|
||||
- '/dclist:'
|
||||
- '/parentdomain'
|
||||
- '/domain_trusts'
|
||||
|
Loading…
Reference in New Issue
Block a user