Update proc_creation_win_lolbin_customshellhost.yml

This commit is contained in:
Florian Roth
2022-08-20 09:22:05 +02:00
committed by GitHub
parent 544e06ee33
commit 65cdc9d04d
@@ -17,7 +17,10 @@ detection:
- Image|endswith: '\CustomShellHost.exe'
- OriginalFileName: 'CustomShellHost.exe'
filter:
Image: 'C:\Windows\explorer.exe'
- Image:
- 'C:\Windows\explorer.exe'
- 'C:\Windows\System32\explorer.exe'
- CurrentDirectory|startswith: C:\Windows\System32\
condition: selection and not filter
falsepositives:
- Unknown