Added wildcards to rule values
These values appear somewhere in a log message, therefore wildcards are required.
This commit is contained in:
@@ -10,14 +10,14 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
keywords:
|
||||
- mimikatz
|
||||
- mimilib
|
||||
- <3 eo.oe
|
||||
- eo.oe.kiwi
|
||||
- privilege::debug
|
||||
- sekurlsa::logonpasswords
|
||||
- lsadump::sam
|
||||
- mimidrv.sys
|
||||
- "* mimikatz *"
|
||||
- "* mimilib *"
|
||||
- "* <3 eo.oe *"
|
||||
- "* eo.oe.kiwi *"
|
||||
- "* privilege::debug *"
|
||||
- "* sekurlsa::logonpasswords *"
|
||||
- "* lsadump::sam *"
|
||||
- "* mimidrv.sys *"
|
||||
condition: keywords
|
||||
falsepositives:
|
||||
- Naughty administrators
|
||||
|
||||
Reference in New Issue
Block a user