Merge branch 'vburov-patch-2'

This commit is contained in:
Thomas Patzke
2019-05-09 23:10:52 +02:00
@@ -13,11 +13,18 @@ logsource:
product: windows
detection:
selection:
CommandLine:
Image:
- '*:\RECYCLER\\*'
- '*:\SystemVolumeInformation\\*'
- '%windir%\Tasks\\*'
- '%systemroot%\debug\\*'
- 'C:\\Windows\\Tasks\\*'
- 'C:\\Windows\\debug\\*'
- 'C:\\Windows\\fonts\\*'
- 'C:\\Windows\\help\\*'
- 'C:\\Windows\\drivers\\*'
- 'C:\\Windows\\addins\\*'
- 'C:\\Windows\\cursors\\*'
- 'C:\\Windows\\system32\tasks\\*'
condition: selection
falsepositives:
- False positives depend on scripts and administrative tools used in the monitored environment