mirror of
https://github.com/valitydev/signature-base.git
synced 2024-11-06 18:15:20 +00:00
Minor changes to rule FP exclusions
This commit is contained in:
parent
f15d1fef2a
commit
8b3a138995
@ -2906,7 +2906,7 @@ rule mimikatz_lsass_mdmp
|
|||||||
strings:
|
strings:
|
||||||
$lsass = "System32\\lsass.exe" wide nocase
|
$lsass = "System32\\lsass.exe" wide nocase
|
||||||
condition:
|
condition:
|
||||||
(uint32(0) == 0x504d444d) and $lsass and filesize > 50000KB and not filename matches /^WER/
|
(uint32(0) == 0x504d444d) and $lsass and filesize > 50000KB and not filename matches /WER/
|
||||||
}
|
}
|
||||||
|
|
||||||
rule wce
|
rule wce
|
||||||
|
@ -300,7 +300,7 @@ rule APT_Cloaked_PsExec
|
|||||||
$s1 = "Sysinternals PsExec" wide fullword
|
$s1 = "Sysinternals PsExec" wide fullword
|
||||||
condition:
|
condition:
|
||||||
uint16(0) == 0x5a4d and $s0 and $s1
|
uint16(0) == 0x5a4d and $s0 and $s1
|
||||||
and not filename matches /^(psexec.exe|PSEXESVC.EXE)$/is
|
and not filename matches /(psexec.exe|PSEXESVC.EXE)$/is
|
||||||
and not filepath matches /RECYCLER\\S-1/
|
and not filepath matches /RECYCLER\\S-1/
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user