fix: missing condition

This commit is contained in:
Florian Roth 2021-05-27 15:04:13 +02:00
parent 7ce7095c2c
commit d5e8d1153f

View File

@ -18,6 +18,7 @@ detection:
EventID: 7045
ServiceName|startswith: 'ProcessHacker'
AccountName: 'LocalSystem'
condition: selection
falsepositives:
- Unlikely
level: high