Update sysmon_win_binary_github_com.yml
This commit is contained in:
@@ -21,10 +21,10 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
Initiated: 'true'
|
||||
DestinationHostname:
|
||||
- '*.github.com'
|
||||
- '*.githubusercontent.com'
|
||||
Image: 'C:\Windows\\*'
|
||||
DestinationHostname|endswith:
|
||||
- '.github.com'
|
||||
- '.githubusercontent.com'
|
||||
Image|startswith: 'C:\Windows\\'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- 'Unknown'
|
||||
|
||||
Reference in New Issue
Block a user