Update powershell_shellcode_b64.yml

This commit is contained in:
Jonhnathan 2020-10-15 17:14:01 -03:00 committed by GitHub
parent 013533fceb
commit efe9c2d3d6
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -21,11 +21,11 @@ logsource:
detection:
selection:
EventID: 4104
keyword1:
- '*AAAAYInlM*'
keyword2:
- '*OiCAAAAYInlM*'
- '*OiJAAAAYInlM*'
keyword1|contains:
- 'AAAAYInlM'
keyword2|contains:
- 'OiCAAAAYInlM'
- 'OiJAAAAYInlM'
condition: selection and keyword1 and keyword2
falsepositives:
- Unknown