Update sysmon_abusing_debug_privilege.yml
This commit is contained in:
@@ -32,7 +32,6 @@ detection:
|
||||
filter:
|
||||
CommandLine|contains|all:
|
||||
- ' route ADD '
|
||||
|
||||
condition: selection1 and selection2 and selection3 and not filter
|
||||
fields:
|
||||
- ParentImage
|
||||
|
||||
Reference in New Issue
Block a user