wrong field name
This commit is contained in:
@@ -15,7 +15,7 @@ detection:
|
||||
cmd_known_url:
|
||||
CommandLine|contains: 'gameplayapi.intel.com'
|
||||
same_parent:
|
||||
ParentProcessName|endswith: '\GfxDownloadWrapper.exe'
|
||||
ParentImage|endswith: '\GfxDownloadWrapper.exe'
|
||||
condition: image_path and not cmd_known_url and not same_parent
|
||||
fields:
|
||||
- CommandLine
|
||||
|
||||
Reference in New Issue
Block a user