Update win_webshell_spawn.yml
This commit is contained in:
@@ -10,18 +10,18 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
ParentImage:
|
||||
- '*\w3wp.exe'
|
||||
- '*\httpd.exe'
|
||||
- '*\nginx.exe'
|
||||
- '*\php-cgi.exe'
|
||||
- '*\tomcat.exe'
|
||||
Image:
|
||||
- '*\cmd.exe'
|
||||
- '*\sh.exe'
|
||||
- '*\bash.exe'
|
||||
- '*\powershell.exe'
|
||||
- '*\bitsadmin.exe'
|
||||
ParentImage|endswith:
|
||||
- '\w3wp.exe'
|
||||
- '\httpd.exe'
|
||||
- '\nginx.exe'
|
||||
- '\php-cgi.exe'
|
||||
- '\tomcat.exe'
|
||||
Image|endswith:
|
||||
- '\cmd.exe'
|
||||
- '\sh.exe'
|
||||
- '\bash.exe'
|
||||
- '\powershell.exe'
|
||||
- '\bitsadmin.exe'
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
||||
Reference in New Issue
Block a user