Update win_powershell_download.yml

This commit is contained in:
Jonhnathan 2020-10-15 18:21:32 -03:00 committed by GitHub
parent cb57e08bc0
commit c47fb4708f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -13,12 +13,12 @@ logsource:
product: windows
detection:
selection:
Image: '*\powershell.exe'
CommandLine:
- '*new-object system.net.webclient).downloadstring(*'
- '*new-object system.net.webclient).downloadfile(*'
- '*new-object net.webclient).downloadstring(*'
- '*new-object net.webclient).downloadfile(*'
Image|endswith: '\powershell.exe'
CommandLine|contains:
- 'new-object system.net.webclient).downloadstring('
- 'new-object system.net.webclient).downloadfile('
- 'new-object net.webclient).downloadstring('
- 'new-object net.webclient).downloadfile('
condition: selection
fields:
- CommandLine