rule: made it more specific - command line must contain URL

This commit is contained in:
Florian Roth 2019-11-20 09:23:04 +01:00
parent 55e66b1843
commit f9e6a929ba

View File

@ -16,6 +16,7 @@ detection:
selection:
ParentImage: '*\consent.exe'
Image: '*\iexplore.exe'
CommandLine: '* http*'
rights1:
IntegrityLevel: 'System' # for Sysmon users
rights2: