update for Image instead of CommandLine

This commit is contained in:
AaronHerman
2022-10-01 19:13:31 -05:00
parent 0710acf9e7
commit 47cd3d4e7b
@@ -15,7 +15,7 @@ logsource:
product: windows
detection:
selection_lolbin:
CommandLine|contains:
Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
selection_exetensions: