Update proc_creation_win_tool_nircmd.yml

This commit is contained in:
Qasim Qlf
2023-02-03 14:40:40 +05:00
committed by GitHub
parent 6279532a13
commit 5505ff28d9
@@ -8,7 +8,7 @@ references:
- https://www.nirsoft.net/utils/nircmd2.html#using
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali
date: 2022/01/24
modified: 2022/11/30
modified: 2023/02/03
tags:
- attack.execution
- attack.t1569.002
@@ -34,7 +34,7 @@ detection:
CommandLine|contains:
- ' show '
- ' hide '
condition: 1 of selection* or all of combo_*
condition: 1 of selection_* or all of combo_*
fields:
- CommandLine
- ParentCommandLine