This commit is contained in:
frack113
2022-03-07 19:37:33 +01:00
parent f9c0e21323
commit 143f5fe4e2
2 changed files with 2 additions and 2 deletions
@@ -21,7 +21,7 @@ logsource:
definition: PowerShell Module Logging must be enabled
detection:
selection_4103:
Payload|conatins|all:
Payload|contains|all:
- 'new-object'
- 'text.encoding]::ascii'
Payload|contains:
@@ -13,7 +13,7 @@ logsource:
detection:
selection:
CommandLine|contains|all:
- 'wuauclt.exe
- 'wuauclt.exe'
- '/UpdateDeploymentProvider'
- '/Runhandlercomserver'
filter: