Update proc_creation_win_susp_gpresult.yml

This commit is contained in:
frack113
2022-05-02 18:13:03 +02:00
committed by GitHub
parent e5a30a7b89
commit 315a79fcf0
@@ -14,8 +14,7 @@ logsource:
category: process_creation
detection:
selection:
Image|endswith:
- '\gpresult.exe'
Image|endswith: '\gpresult.exe'
CommandLine|contains:
- '/z'
- '/v'
@@ -25,4 +24,4 @@ falsepositives:
level: medium
tags:
- attack.discovery
- attack.t1615
- attack.t1615