Update proc_creation_win_change_evtx_location.yml

This commit is contained in:
Vadim
2023-01-03 12:11:13 +03:00
committed by GitHub
parent 2075962596
commit 052cd2e967
@@ -19,7 +19,7 @@ detection:
CommandLine|contains|all:
- wevtutil
- /lfn
- \.evtx
- .evtx
filter_cmd:
CommandLine|contains: \Windows\System32\winevt\Logs
condition: selection_cmd and not filter_cmd