mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
rule: made it more specific - command line must contain URL
This commit is contained in:
parent
55e66b1843
commit
f9e6a929ba
@ -16,6 +16,7 @@ detection:
|
|||||||
selection:
|
selection:
|
||||||
ParentImage: '*\consent.exe'
|
ParentImage: '*\consent.exe'
|
||||||
Image: '*\iexplore.exe'
|
Image: '*\iexplore.exe'
|
||||||
|
CommandLine: '* http*'
|
||||||
rights1:
|
rights1:
|
||||||
IntegrityLevel: 'System' # for Sysmon users
|
IntegrityLevel: 'System' # for Sysmon users
|
||||||
rights2:
|
rights2:
|
||||||
|
Loading…
Reference in New Issue
Block a user