Update win_susp_powershell_enc_cmd.yml

This commit is contained in:
Jonhnathan 2020-11-28 13:04:36 -03:00 committed by GitHub
parent 53e1201bea
commit f4f8174199
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,15 +17,12 @@ logsource:
detection:
selection:
CommandLine|contains:
- ' -e'
- ' -en'
- ' -enc'
- ' -e' #Covers -en and -enc
- ' -w hidden -e'
selection2:
- 'JAB'
selection3:
- '-e'
- '-enc'
- '-e' #Covers -en and -enc
selection4:
- ' BA^J'
- ' SUVYI'