Fix yml
This commit is contained in:
+1
-1
@@ -21,7 +21,7 @@ logsource:
|
||||
definition: PowerShell Module Logging must be enabled
|
||||
detection:
|
||||
selection_4103:
|
||||
Payload|conatins|all:
|
||||
Payload|contains|all:
|
||||
- 'new-object'
|
||||
- 'text.encoding]::ascii'
|
||||
Payload|contains:
|
||||
|
||||
@@ -13,7 +13,7 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
CommandLine|contains|all:
|
||||
- 'wuauclt.exe
|
||||
- 'wuauclt.exe'
|
||||
- '/UpdateDeploymentProvider'
|
||||
- '/Runhandlercomserver'
|
||||
filter:
|
||||
|
||||
Reference in New Issue
Block a user