Update sysmon_susp_adsi_cache_usage.yml
This commit is contained in:
@@ -18,7 +18,7 @@ logsource:
|
||||
category: file_event
|
||||
detection:
|
||||
selection_1:
|
||||
TargetFilename: '*\Local\Microsoft\Windows\SchCache\\*.sch'
|
||||
TargetFilename|endswith: '\Local\Microsoft\Windows\SchCache\\*.sch'
|
||||
selection_2:
|
||||
Image:
|
||||
- 'C:\windows\system32\svchost.exe'
|
||||
|
||||
Reference in New Issue
Block a user