mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
Update sysmon_cactustorch.yml
This commit is contained in:
parent
457217bfc0
commit
df81f5180d
@ -14,13 +14,13 @@ logsource:
|
|||||||
detection:
|
detection:
|
||||||
selection:
|
selection:
|
||||||
EventID: 8
|
EventID: 8
|
||||||
SourceImage:
|
SourceImage|endswith:
|
||||||
- '*\System32\cscript.exe'
|
- '\System32\cscript.exe'
|
||||||
- '*\System32\wscript.exe'
|
- '\System32\wscript.exe'
|
||||||
- '*\System32\mshta.exe'
|
- '\System32\mshta.exe'
|
||||||
- '*\winword.exe'
|
- '\winword.exe'
|
||||||
- '*\excel.exe'
|
- '\excel.exe'
|
||||||
TargetImage: '*\SysWOW64\\*'
|
TargetImage|contains: '\SysWOW64\\'
|
||||||
StartModule: null
|
StartModule: null
|
||||||
condition: selection
|
condition: selection
|
||||||
tags:
|
tags:
|
||||||
|
Loading…
Reference in New Issue
Block a user