fix: other locations
https://twitter.com/ber_m1ng/status/1397948048135778309
This commit is contained in:
@@ -22,7 +22,7 @@ detection:
|
||||
- '\regsvr32.exe'
|
||||
filter1:
|
||||
ParentImage|contains:
|
||||
- '\AppData\Local\Temp\'
|
||||
- '\AppData\Local\'
|
||||
- '\Microsoft\Edge\'
|
||||
condition: selection and not filter1
|
||||
fields:
|
||||
|
||||
@@ -16,7 +16,7 @@ detection:
|
||||
ParentImage|endswith: '\svchost.exe'
|
||||
filter2:
|
||||
ParentImage|contains:
|
||||
- '\AppData\Local\Temp\'
|
||||
- '\AppData\Local\'
|
||||
- '\Microsoft\Edge\'
|
||||
condition: selection and not filter1 and not filter2
|
||||
fields:
|
||||
|
||||
Reference in New Issue
Block a user