Removed duplicate

This commit is contained in:
Florian Roth
2017-04-13 01:21:46 +02:00
parent c2ed7bd9df
commit 059cfbf15a
@@ -1,17 +0,0 @@
title: Suspicious MSHTA Child
status: experimental
description: Detects a Microsoft HTML Application Host execution a suspicious child process
reference: https://twitter.com/wdormann/status/851615583099650049
author: Florian Roth
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
ParentImage: '*\mshta.exe'
condition: selection
falsepositives:
- unknown
level: high