Merge pull request #1263 from Neo23x0/rule-devel
feat: cover newest emotet campaigns
This commit is contained in:
@@ -40,6 +40,7 @@ detection:
|
||||
- '* -e* IAB*'
|
||||
- '* -e* UwB*'
|
||||
- '* -e* cwB*'
|
||||
- '*.exe -ENCOD *'
|
||||
falsepositive1:
|
||||
CommandLine: '* -ExecutionPolicy remotesigned *'
|
||||
condition: selection and not falsepositive1
|
||||
|
||||
Reference in New Issue
Block a user