mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Removed within keyword in rule
This commit is contained in:
parent
0df60fe004
commit
c865b0e9a8
@ -51,9 +51,8 @@ detection:
|
||||
- wbadmin.exe
|
||||
- icacls.exe
|
||||
- diskpart.exe
|
||||
# timeframe: 30min
|
||||
timeframe: 5min
|
||||
condition: selection | count() > 5 within timeframe
|
||||
condition: selection | count() > 5
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
level: medium
|
||||
|
Loading…
Reference in New Issue
Block a user