fix: FPs with Armitage_MeterpreterSession_Strings on proc mem

This commit is contained in:
Florian Roth 2020-05-19 09:19:43 +02:00
parent 8e7d4a1158
commit 3aee93a2ee

View File

@ -45,8 +45,7 @@ rule Armitage_MeterpreterSession_Strings {
$s1 = "session.meterpreter_read" fullword ascii
$s2 = "sniffer_dump" fullword ascii
$s3 = "keyscan_dump" fullword ascii
$s4 = "mimikatz_command" fullword ascii
$s5 = "MeterpreterSession.java" fullword ascii
$s4 = "MeterpreterSession.java" fullword ascii
condition:
filesize < 30KB and 1 of them
}