rule: made it more specific - command line must contain URL

This commit is contained in:
Florian Roth 2019-11-20 09:23:04 +01:00
parent 55e66b1843
commit f9e6a929ba

View File

@ -16,6 +16,7 @@ detection:
selection: selection:
ParentImage: '*\consent.exe' ParentImage: '*\consent.exe'
Image: '*\iexplore.exe' Image: '*\iexplore.exe'
CommandLine: '* http*'
rights1: rights1:
IntegrityLevel: 'System' # for Sysmon users IntegrityLevel: 'System' # for Sysmon users
rights2: rights2: