mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
fe9b91c504
changed to the following to follow rule creation guidelines: - Image|endswith: '\wbem\WMIC.exe' - ProcessCommandLine|contains: 'wmic ' |
||
---|---|---|
.. | ||
application | ||
apt | ||
cloud | ||
compliance | ||
generic | ||
linux | ||
network | ||
proxy | ||
web | ||
windows |