Improved shell spawning rule

This commit is contained in:
Florian Roth
2018-04-11 20:09:28 +02:00
parent ef7fb4cff1
commit 52d405bb1b
@@ -24,6 +24,7 @@ detection:
- '*\nslookup.exe'
- '*\certutil.exe'
- '*\bitsadmin.exe'
- '*\mshta.exe'
condition: selection
fields:
- CommandLine