mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
fix
This commit is contained in:
parent
29cd7fed3e
commit
ebe4fe0377
@ -13,8 +13,8 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
Image: '*\rundll32.exe'
|
||||
CommandLine: '*comsvcs.dll*minidump*'
|
||||
Image:'*\rundll32.exe'
|
||||
CommandLine:'*comsvcs.dll*minidump*'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- unknown
|
||||
|
@ -15,9 +15,9 @@ detection:
|
||||
selection:
|
||||
EventID: 8
|
||||
TargetProcessAddress:
|
||||
- '*0B80'
|
||||
- '*0C7C'
|
||||
- '*0C88'
|
||||
-'*0B80'
|
||||
-'*0C7C'
|
||||
-'*0C88'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- unknown
|
||||
|
@ -15,8 +15,8 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 4688
|
||||
ProcessName: '*\fltMC.exe'
|
||||
CommandLine: '*unload*Sys*'
|
||||
ProcessName:'*\fltMC.exe'
|
||||
CommandLine:'*unload*Sys*'
|
||||
selection1:
|
||||
EventID: 4673
|
||||
PrivilegeList: '*\SeLoadDriverPrivilege'
|
||||
|
Loading…
Reference in New Issue
Block a user