Updated at command rule to use Image field

This commit is contained in:
Roberto Rodriguez
2021-10-15 15:46:59 -04:00
parent aa0a5b8204
commit 04ff9ae692
@@ -11,7 +11,7 @@ logsource:
category: process_creation
detection:
selection:
ProcessName|endswith:
Image|endswith:
- '/at'
- '/atd'
condition: selection