fix: multiple false positive conditions

This commit is contained in:
Florian Roth 2020-01-28 10:11:09 +01:00
parent 240b764660
commit d48fc9d1ff
2 changed files with 6 additions and 2 deletions

View File

@ -18,7 +18,9 @@ detection:
selection:
EventID: 15
filter:
Imphash: '00000000000000000000000000000000'
Imphash:
- '00000000000000000000000000000000'
- null
condition: selection and not filter
fields:
- TargetFilename

View File

@ -24,7 +24,9 @@ detection:
exec_exclusion1:
Image: '*\explorer.exe'
exec_exclusion2:
CommandLine: '*\netlogon.bat'
CommandLine:
- '*\netlogon.bat'
- '*\UsrLogon.cmd'
condition: exec_selection and not exec_exclusion1 and not exec_exclusion2
---
logsource: