Update win_exploit_cve_2017_11882.yml

This commit is contained in:
Jonhnathan 2020-10-15 17:51:20 -03:00 committed by GitHub
parent e163bb18ef
commit e5506f4de1
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -21,7 +21,7 @@ logsource:
product: windows
detection:
selection:
ParentImage: '*\EQNEDT32.EXE'
ParentImage|endswith: '\EQNEDT32.EXE'
condition: selection
fields:
- CommandLine