Merge branch 'vburov-patch-2'
This commit is contained in:
@@ -13,11 +13,18 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
Image:
|
||||
- '*:\RECYCLER\\*'
|
||||
- '*:\SystemVolumeInformation\\*'
|
||||
- '%windir%\Tasks\\*'
|
||||
- '%systemroot%\debug\\*'
|
||||
- 'C:\\Windows\\Tasks\\*'
|
||||
- 'C:\\Windows\\debug\\*'
|
||||
- 'C:\\Windows\\fonts\\*'
|
||||
- 'C:\\Windows\\help\\*'
|
||||
- 'C:\\Windows\\drivers\\*'
|
||||
- 'C:\\Windows\\addins\\*'
|
||||
- 'C:\\Windows\\cursors\\*'
|
||||
- 'C:\\Windows\\system32\tasks\\*'
|
||||
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
|
||||
Reference in New Issue
Block a user