diff --git a/other/godmode_sigma_rule.yml b/other/godmode_sigma_rule.yml index 9c90a426a..c5292a1db 100644 --- a/other/godmode_sigma_rule.yml +++ b/other/godmode_sigma_rule.yml @@ -56,8 +56,7 @@ detection: - ' comsvcs.dll,#24' # Process dumping method apart from procdump - ' comsvcs.dll MiniDump' # Process dumping method apart from procdump - ' comsvcs.dll #24' # Process dumping method apart from procdump - - 'MiniDump full' # Process dumping method apart from procdump - - '#24 full' # Process dumping method apart from procdump + - '.dmp full' # Process dumping method apart from procdump selection_parent_child: ParentImage|contains: # Office Dropper Detection