Update rules/windows/process_creation/proc_creation_win_rar_susp_greedy.yml

Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
Florian Roth
2022-12-27 15:46:37 +01:00
committed by GitHub
parent 47572e08c8
commit 32a17342b4
@@ -27,7 +27,8 @@ detection:
- ' -r ' # recursive
selection_folders:
CommandLine|contains:
- ' C:\\*.'
- ' C:\\\*.'
- ' C:\\\\\*.'
- ' C:\Users\Public\'
- ' %public%'
- ' C:\Windows\'