mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
fix: error in selector
This commit is contained in:
parent
530e04faec
commit
e516aecc74
@ -12,7 +12,7 @@ logsource:
|
|||||||
category: process_creation
|
category: process_creation
|
||||||
product: windows
|
product: windows
|
||||||
detection:
|
detection:
|
||||||
selection_image1:
|
selection:
|
||||||
Image|endswith:
|
Image|endswith:
|
||||||
- '\powershell.exe'
|
- '\powershell.exe'
|
||||||
- '\mshta.exe'
|
- '\mshta.exe'
|
||||||
|
Loading…
Reference in New Issue
Block a user