Improved shell spawning rule
This commit is contained in:
@@ -24,6 +24,7 @@ detection:
|
||||
- '*\nslookup.exe'
|
||||
- '*\certutil.exe'
|
||||
- '*\bitsadmin.exe'
|
||||
- '*\mshta.exe'
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
||||
Reference in New Issue
Block a user