Update silenttrinity_stager_msbuild_activity.yml
This commit is contained in:
@@ -19,7 +19,7 @@ detection:
|
||||
- '443'
|
||||
Initiated: 'true'
|
||||
filter:
|
||||
ParentImage|endswith: '*\msbuild.exe'
|
||||
ParentImage|endswith: '\msbuild.exe'
|
||||
condition: selection and filter
|
||||
falsepositives:
|
||||
- unknown
|
||||
|
||||
Reference in New Issue
Block a user