Update av_webshell.yml

This commit is contained in:
Jonhnathan 2020-10-27 22:35:45 -03:00 committed by GitHub
parent 0afe48a0a0
commit dbad6c637f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -14,14 +14,15 @@ logsource:
product: antivirus
detection:
selection:
Signature|startswith:
- Signature|startswith:
- "PHP/Backdoor"
- "JSP/Backdoor"
- "ASP/Backdoor"
- "Backdoor.PHP"
- "Backdoor.JSP"
- "Backdoor.ASP"
- "*Webshell"
- Signature|contains:
- "Webshell"
condition: selection
fields:
- FileName