Update win_proc_wrong_parent.yml

This commit is contained in:
Jonhnathan
2020-10-15 18:23:03 -03:00
committed by GitHub
parent 1f76c1f897
commit 64c63c8d38
@@ -20,22 +20,22 @@ logsource:
product: windows
detection:
selection:
Image:
- '*\svchost.exe'
- '*\taskhost.exe'
- '*\lsm.exe'
- '*\lsass.exe'
- '*\services.exe'
- '*\lsaiso.exe'
- '*\csrss.exe'
- '*\wininit.exe'
- '*\winlogon.exe'
Image|endswith:
- '\svchost.exe'
- '\taskhost.exe'
- '\lsm.exe'
- '\lsass.exe'
- '\services.exe'
- '\lsaiso.exe'
- '\csrss.exe'
- '\wininit.exe'
- '\winlogon.exe'
filter:
ParentImage:
- '*\System32\\*'
- '*\SysWOW64\\*'
- '*\SavService.exe'
- '*\Windows Defender\\*\MsMpEng.exe'
ParentImage|endswith:
- '\System32\\*'
- '\SysWOW64\\*'
- '\SavService.exe'
- '\Windows Defender\\*\MsMpEng.exe'
filter_null:
ParentImage: null
condition: selection and not filter and not filter_null