Merge pull request #389 from christophetd/patch-1

Include Github raw URLs in suspicious downloads detection rule
This commit is contained in:
Florian Roth
2019-07-05 16:54:09 +02:00
committed by GitHub
@@ -18,6 +18,7 @@ detection:
DestinationHostname:
- '*dl.dropboxusercontent.com'
- '*.pastebin.com'
- '*.githubusercontent.com' # includes both gists and github repositories
Image: 'C:\Windows\\*'
condition: selection
falsepositives: