mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_susp_execution_path.yml
This commit is contained in:
parent
9ef41cbc77
commit
fedc5b88e0
@ -12,16 +12,16 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
Image:
|
||||
- '*\$Recycle.bin'
|
||||
- '*\Users\All Users\\*'
|
||||
- '*\Users\Default\\*'
|
||||
- '*\Users\Public\\*'
|
||||
- 'C:\Perflogs\\*'
|
||||
- '*\config\systemprofile\\*'
|
||||
- '*\Windows\Fonts\\*'
|
||||
- '*\Windows\IME\\*'
|
||||
- '*\Windows\addins\\*'
|
||||
Image|contains:
|
||||
- '\$Recycle.bin'
|
||||
- '\Users\All Users\\'
|
||||
- '\Users\Default\\'
|
||||
- '\Users\Public\\'
|
||||
- 'C:\Perflogs\\'
|
||||
- '\config\systemprofile\\'
|
||||
- '\Windows\Fonts\\'
|
||||
- '\Windows\IME\\'
|
||||
- '\Windows\addins\\'
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
Loading…
Reference in New Issue
Block a user