Update sysmon_abusing_debug_privilege.yml
French language settings
This commit is contained in:
@@ -28,7 +28,9 @@ detection:
|
||||
- '\powershell.exe'
|
||||
- '\cmd.exe'
|
||||
selection3:
|
||||
User: 'NT AUTHORITY\SYSTEM'
|
||||
User|startswith:
|
||||
- 'NT AUTHORITY\SYSTEM'
|
||||
- 'AUTORITE NT\Sys' # French language settings
|
||||
filter:
|
||||
CommandLine|contains|all:
|
||||
- ' route '
|
||||
|
||||
Reference in New Issue
Block a user