Merge pull request #389 from christophetd/patch-1
Include Github raw URLs in suspicious downloads detection rule
This commit is contained in:
@@ -18,6 +18,7 @@ detection:
|
||||
DestinationHostname:
|
||||
- '*dl.dropboxusercontent.com'
|
||||
- '*.pastebin.com'
|
||||
- '*.githubusercontent.com' # includes both gists and github repositories
|
||||
Image: 'C:\Windows\\*'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user