Update sysmon_process_hollowing.yml
This commit is contained in:
@@ -20,7 +20,7 @@ detection:
|
||||
filters:
|
||||
Image|endswith:
|
||||
- '\chrome.exe'
|
||||
- '\opeara.exe'
|
||||
- '\opera.exe'
|
||||
- '\firefox.exe'
|
||||
- '\MicrosoftEdge.exe'
|
||||
condition: selection and not filters
|
||||
|
||||
Reference in New Issue
Block a user