Merge pull request #569 from Neo23x0/devel

rule: improved bloodhound rule
This commit is contained in:
Florian Roth
2019-12-20 17:32:21 +01:00
committed by GitHub
@@ -19,6 +19,7 @@ detection:
selection2:
CommandLine|contains:
- ' -CollectionMethod All '
- '.exe -c All -d '
- 'Invoke-Bloodhound'
- 'Get-BloodHoundData'
selection3: