Merge branch 'rule-devel' of https://github.com/SigmaHQ/sigma into rule-devel

This commit is contained in:
Florian Roth
2021-08-24 12:30:42 +02:00
@@ -13,7 +13,7 @@ detection:
selection:
Image|endswith: '\splwow64.exe'
filter:
CommandLine|contains: 'splwow64.exe '
CommandLine|endswith: 'splwow64.exe'
condition: selection and not filter
falsepositives:
- Unknown