mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Update sysmon_notepad_network_connection.yml
This commit is contained in:
parent
b479cbdb10
commit
e20027965f
@ -18,7 +18,7 @@ date: 2020/05/14
|
||||
modified: 2020/08/24
|
||||
detection:
|
||||
selection:
|
||||
Image: '*\notepad.exe'
|
||||
Image|endswith: '\notepad.exe'
|
||||
filter:
|
||||
DestinationPort: '9100'
|
||||
condition: selection and not filter
|
||||
|
Loading…
Reference in New Issue
Block a user