Deleted EventID part

This commit is contained in:
Furkan ÇALIŞKAN
2020-06-04 18:19:08 +03:00
committed by GitHub
parent 1c677aa172
commit 0744107fbb
@@ -13,7 +13,6 @@ logsource:
product: windows
detection:
selection:
EventID: 1
Image|endswith:
- '\powershell.exe'
ParentImage|endswith: