Update win_apt_apt29_thinktanks.yml

This commit is contained in:
Jonhnathan 2020-10-27 23:24:04 -03:00 committed by GitHub
parent 467af2ebb5
commit e24e6da3b5
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,7 +17,11 @@ logsource:
product: windows
detection:
selection:
CommandLine|contains: '-noni -ep bypass $'
CommandLine|contains|all:
- '-noni'
- '-ep'
- 'bypass'
- '$'
condition: selection
falsepositives:
- unknown