Update sysmon_susp_adsi_cache_usage.yml

This commit is contained in:
Jonhnathan
2020-10-15 16:01:46 -03:00
committed by GitHub
parent 9eedeabda9
commit 5790cc2ea7
@@ -18,7 +18,7 @@ logsource:
category: file_event
detection:
selection_1:
TargetFilename: '*\Local\Microsoft\Windows\SchCache\\*.sch'
TargetFilename|endswith: '\Local\Microsoft\Windows\SchCache\\*.sch'
selection_2:
Image:
- 'C:\windows\system32\svchost.exe'