Update proc_creation_win_tool_nircmd.yml
This commit is contained in:
@@ -8,7 +8,7 @@ references:
|
||||
- https://www.nirsoft.net/utils/nircmd2.html#using
|
||||
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali
|
||||
date: 2022/01/24
|
||||
modified: 2022/11/30
|
||||
modified: 2023/02/03
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1569.002
|
||||
@@ -34,7 +34,7 @@ detection:
|
||||
CommandLine|contains:
|
||||
- ' show '
|
||||
- ' hide '
|
||||
condition: 1 of selection* or all of combo_*
|
||||
condition: 1 of selection_* or all of combo_*
|
||||
fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
|
||||
Reference in New Issue
Block a user