fix: null value in separate expression
This commit is contained in:
@@ -18,8 +18,9 @@ detection:
|
||||
- '*\MsMpEng.exe'
|
||||
- '*\Mrt.exe'
|
||||
- '*\rpcnet.exe'
|
||||
- null
|
||||
condition: selection and not filter
|
||||
filter_null:
|
||||
ParentImage: null
|
||||
condition: selection and not filter and not filter_null
|
||||
fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
|
||||
Reference in New Issue
Block a user