From 7a5017696fddafaa68eed8cc07b09e6e2fb90a69 Mon Sep 17 00:00:00 2001 From: "nasreddine.bencherchali@nextron-systems.com" <8741929+nasbench@users.noreply.github.com> Date: Fri, 16 Sep 2022 09:23:15 +0200 Subject: [PATCH] Add more flag to curl windows rule --- .../proc_creation_win_susp_curl_fileupload.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/rules/windows/process_creation/proc_creation_win_susp_curl_fileupload.yml b/rules/windows/process_creation/proc_creation_win_susp_curl_fileupload.yml index 20ffcba7a..44c6f4373 100644 --- a/rules/windows/process_creation/proc_creation_win_susp_curl_fileupload.yml +++ b/rules/windows/process_creation/proc_creation_win_susp_curl_fileupload.yml @@ -9,7 +9,7 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-19---curl-upload-file - https://curl.se/docs/manpage.html date: 2020/07/03 -modified: 2022/01/22 +modified: 2022/09/15 logsource: category: process_creation product: windows @@ -21,10 +21,12 @@ detection: CommandLine|contains: - ' -F ' - ' --form ' + - ' --form-string ' - ' -T ' - ' --upload-file ' - ' -d ' - ' --data ' + - ' --data-' # For flags like: "--data-ascii", "--data-binary", "--data-raw", "--data-urlencode" condition: all of selection* fields: - CommandLine