Update proc_creation_win_change_evtx_location.yml
This commit is contained in:
@@ -19,7 +19,7 @@ detection:
|
||||
CommandLine|contains|all:
|
||||
- wevtutil
|
||||
- /lfn
|
||||
- \.evtx
|
||||
- .evtx
|
||||
filter_cmd:
|
||||
CommandLine|contains: \Windows\System32\winevt\Logs
|
||||
condition: selection_cmd and not filter_cmd
|
||||
|
||||
Reference in New Issue
Block a user