Update win_pc_sqlcmd_veeam_dump.yml

This commit is contained in:
Florian Roth
2021-12-21 13:28:47 +01:00
committed by GitHub
parent 6e19e75ece
commit 59bfca6aba
@@ -15,7 +15,7 @@ logsource:
product: windows
detection:
selection_tools:
Image|endswith: 'sqlcmd.exe'
Image|endswith: '\sqlcmd.exe'
selection_query:
CommandLine|contains|all:
- 'SELECT'