Update sysmon_abusing_debug_privilege.yml

French language settings
This commit is contained in:
mlp1515
2021-08-26 12:46:15 +00:00
committed by GitHub
parent a31422db74
commit 4f49f03460
@@ -28,7 +28,9 @@ detection:
- '\powershell.exe'
- '\cmd.exe'
selection3:
User: 'NT AUTHORITY\SYSTEM'
User|startswith:
- 'NT AUTHORITY\SYSTEM'
- 'AUTORITE NT\Sys' # French language settings
filter:
CommandLine|contains|all:
- ' route '