wrong field name

This commit is contained in:
Florian Roth
2020-11-28 10:10:00 +01:00
committed by GitHub
parent 84dc11ca98
commit 1ea4bb0b87
@@ -15,7 +15,7 @@ detection:
cmd_known_url:
CommandLine|contains: 'gameplayapi.intel.com'
same_parent:
ParentProcessName|endswith: '\GfxDownloadWrapper.exe'
ParentImage|endswith: '\GfxDownloadWrapper.exe'
condition: image_path and not cmd_known_url and not same_parent
fields:
- CommandLine