Updated at command rule to use Image field
This commit is contained in:
@@ -11,7 +11,7 @@ logsource:
|
||||
category: process_creation
|
||||
detection:
|
||||
selection:
|
||||
ProcessName|endswith:
|
||||
Image|endswith:
|
||||
- '/at'
|
||||
- '/atd'
|
||||
condition: selection
|
||||
Reference in New Issue
Block a user