mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 02:08:54 +00:00
rule: made it more specific - command line must contain URL
This commit is contained in:
parent
55e66b1843
commit
f9e6a929ba
@ -16,6 +16,7 @@ detection:
|
||||
selection:
|
||||
ParentImage: '*\consent.exe'
|
||||
Image: '*\iexplore.exe'
|
||||
CommandLine: '* http*'
|
||||
rights1:
|
||||
IntegrityLevel: 'System' # for Sysmon users
|
||||
rights2:
|
||||
|
Loading…
Reference in New Issue
Block a user