mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Update av_webshell.yml
This commit is contained in:
parent
0afe48a0a0
commit
dbad6c637f
@ -14,14 +14,15 @@ logsource:
|
||||
product: antivirus
|
||||
detection:
|
||||
selection:
|
||||
Signature|startswith:
|
||||
- Signature|startswith:
|
||||
- "PHP/Backdoor"
|
||||
- "JSP/Backdoor"
|
||||
- "ASP/Backdoor"
|
||||
- "Backdoor.PHP"
|
||||
- "Backdoor.JSP"
|
||||
- "Backdoor.ASP"
|
||||
- "*Webshell"
|
||||
- Signature|contains:
|
||||
- "Webshell"
|
||||
condition: selection
|
||||
fields:
|
||||
- FileName
|
||||
|
Loading…
Reference in New Issue
Block a user