Update sysmon_process_hollowing.yml

This commit is contained in:
Florian Roth
2022-02-01 16:01:27 +01:00
committed by GitHub
parent e16974522b
commit 7f9fd3ea63
@@ -20,7 +20,7 @@ detection:
filters:
Image|endswith:
- '\chrome.exe'
- '\opeara.exe'
- '\opera.exe'
- '\firefox.exe'
- '\MicrosoftEdge.exe'
condition: selection and not filters