mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Update sysmon_cactustorch.yml
This commit is contained in:
parent
457217bfc0
commit
df81f5180d
@ -14,13 +14,13 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 8
|
||||
SourceImage:
|
||||
- '*\System32\cscript.exe'
|
||||
- '*\System32\wscript.exe'
|
||||
- '*\System32\mshta.exe'
|
||||
- '*\winword.exe'
|
||||
- '*\excel.exe'
|
||||
TargetImage: '*\SysWOW64\\*'
|
||||
SourceImage|endswith:
|
||||
- '\System32\cscript.exe'
|
||||
- '\System32\wscript.exe'
|
||||
- '\System32\mshta.exe'
|
||||
- '\winword.exe'
|
||||
- '\excel.exe'
|
||||
TargetImage|contains: '\SysWOW64\\'
|
||||
StartModule: null
|
||||
condition: selection
|
||||
tags:
|
||||
|
Loading…
Reference in New Issue
Block a user