Update proc_creation_win_uac_bypass_idiagnostic_profile.yml
This commit is contained in:
@@ -12,7 +12,7 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
ParentImage|endswith: '\DllHost.exe'
|
||||
ParentCommandLine|contains: ' /Processid:{2C21EA7-2EB8-4B55-9249-AC243DA8C666}'
|
||||
ParentCommandLine|contains: ' /Processid:{12C21EA7-2EB8-4B55-9249-AC243DA8C666}'
|
||||
IntegrityLevel:
|
||||
- 'High'
|
||||
- 'System'
|
||||
|
||||
Reference in New Issue
Block a user