SigmaHQ/wazuh/rules/sigma_win_susp_devtoolslauncher.yml
joker2013 50379800f2 123
2020-12-03 01:43:30 +03:00

16 lines
360 B
YAML

alert:
- debug
description: The Devtoolslauncher.exe executes other binary
filter:
- query:
query_string:
query: (data.win.eventdata.image.keyword:*\\devtoolslauncher.exe AND data.win.eventdata.commandLine.keyword:*LaunchForDeploy*)
index: wazuh-alerts-3.x-*
name: cc268ac1-42d9-40fd-9ed3-8c4e1a5b87e6_0
priority: 1
realert:
minutes: 0
type: any