Update rules/windows/process_creation/proc_creation_win_rar_susp_greedy.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
@@ -27,7 +27,8 @@ detection:
|
||||
- ' -r ' # recursive
|
||||
selection_folders:
|
||||
CommandLine|contains:
|
||||
- ' C:\\*.'
|
||||
- ' C:\\\*.'
|
||||
- ' C:\\\\\*.'
|
||||
- ' C:\Users\Public\'
|
||||
- ' %public%'
|
||||
- ' C:\Windows\'
|
||||
|
||||
Reference in New Issue
Block a user