Update win_invoke_obfuscation_via_rundll.yml

This commit is contained in:
Timur Zinniatullin 2020-10-18 19:05:40 +03:00 committed by GitHub
parent eb2af704e7
commit d84281936b
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -16,7 +16,7 @@ logsource:
product: windows product: windows
detection: detection:
selection: selection:
- CommandLine|re: '(?i).*rundll32(?:.exe)?(?:\s+)?shell32\.dll.*shellexec_rundll.*powershell.*\"' - CommandLine|re: '(?i).*rundll32(?:\.exe)?(?:\s+)?shell32\.dll.*shellexec_rundll.*powershell.*\"'
condition: selection condition: selection
falsepositives: falsepositives:
- Unknown - Unknown