Update win_susp_iss_module_install.yml
This commit is contained in:
@@ -15,8 +15,8 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
- '*\APPCMD.EXE install module /name:*'
|
||||
CommandLine|contains:
|
||||
- '\APPCMD.EXE install module /name:'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown as it may vary from organisation to arganisation how admins use to install IIS modules
|
||||
|
||||
Reference in New Issue
Block a user