fix: wrong cmdline combos
This commit is contained in:
@@ -56,8 +56,7 @@ detection:
|
||||
- ' comsvcs.dll,#24' # Process dumping method apart from procdump
|
||||
- ' comsvcs.dll MiniDump' # Process dumping method apart from procdump
|
||||
- ' comsvcs.dll #24' # Process dumping method apart from procdump
|
||||
- 'MiniDump full' # Process dumping method apart from procdump
|
||||
- '#24 full' # Process dumping method apart from procdump
|
||||
- '.dmp full' # Process dumping method apart from procdump
|
||||
selection_parent_child:
|
||||
ParentImage|contains:
|
||||
# Office Dropper Detection
|
||||
|
||||
Reference in New Issue
Block a user