modifed win_susp_odbcconf.yml
This commit is contained in:
@@ -13,9 +13,9 @@ logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
Image: '*\odbcconf.exe'
|
||||
CommandLine: '* -f *.rsp'
|
||||
selection:
|
||||
Image: '*\odbcconf.exe'
|
||||
CommandLine: '* -f *.rsp'
|
||||
condition: selection
|
||||
level: medium
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user