Update win_susp_sysprep_appdata.yml

This commit is contained in:
Jonhnathan
2020-10-15 19:49:12 -03:00
committed by GitHub
parent 4c9124952e
commit 08a018a2ee
@@ -15,9 +15,9 @@ logsource:
product: windows
detection:
selection:
CommandLine:
- '*\sysprep.exe *\AppData\\*'
- sysprep.exe *\AppData\\*
CommandLine|contains|all:
- 'sysprep.exe'
- '\AppData\\'
condition: selection
falsepositives:
- False positives depend on scripts and administrative tools used in the monitored environment