Remove too loose filter in mshta rule

This commit is contained in:
Karneades 2019-04-04 22:16:24 +02:00 committed by GitHub
parent 81693d81b6
commit eb690d8902
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -20,10 +20,6 @@ detection:
- '*\reg.exe'
- '*\regsvr32.exe'
- '*\BITSADMIN*'
filter:
CommandLine:
- '*/HP/HP*'
- '*\HP\HP*'
condition: selection and not filter
fields:
- CommandLine