Update sysmon_win_binary_github_com.yml

This commit is contained in:
Jonhnathan
2020-10-15 16:26:28 -03:00
committed by GitHub
parent 554adb8562
commit 5dc02f3a87
@@ -21,10 +21,10 @@ logsource:
detection:
selection:
Initiated: 'true'
DestinationHostname:
- '*.github.com'
- '*.githubusercontent.com'
Image: 'C:\Windows\\*'
DestinationHostname|endswith:
- '.github.com'
- '.githubusercontent.com'
Image|startswith: 'C:\Windows\\'
condition: selection
falsepositives:
- 'Unknown'