Update win_susp_iss_module_install.yml

This commit is contained in:
Jonhnathan
2020-10-15 19:30:56 -03:00
committed by GitHub
parent cd6149bcc3
commit 0e1ae89a5c
@@ -15,8 +15,8 @@ logsource:
product: windows
detection:
selection:
CommandLine:
- '*\APPCMD.EXE install module /name:*'
CommandLine|contains:
- '\APPCMD.EXE install module /name:'
condition: selection
falsepositives:
- Unknown as it may vary from organisation to arganisation how admins use to install IIS modules