mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Clean rule rules/windows/malware/win_mal_octopus_scanner.yml to use category
This commit is contained in:
parent
a9f2a80b8c
commit
cce8d945a0
@ -13,12 +13,11 @@ logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
detection:
|
||||
filecreate:
|
||||
selection:
|
||||
TargetFilename|endswith:
|
||||
- '\AppData\Local\Microsoft\Cache134.dat'
|
||||
- '\AppData\Local\Microsoft\ExplorerSync.db'
|
||||
condition: filecreate and selection
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: high
|
||||
|
Loading…
Reference in New Issue
Block a user