cleanup win_malware_conti_shadowcopy.yml

This commit is contained in:
frack113
2021-08-16 09:21:04 +02:00
committed by GitHub
parent ed424c55c8
commit 5b09dff1fb
@@ -11,8 +11,7 @@ logsource:
product: windows
detection:
selection_1:
CommandLine|contains:
- '\\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy'
CommandLine|contains: '\\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy'
selection_2:
CommandLine|contains:
- '\\NTDS.dit'