Update image_load_susp_cmstp.yml
This commit is contained in:
@@ -20,8 +20,7 @@ detection:
|
||||
ImageLoaded|endswith:
|
||||
- '.dll'
|
||||
- '.ocx'
|
||||
Image|endswith:
|
||||
- '\cmstp.exe'
|
||||
Image|endswith: '\cmstp.exe'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unikely
|
||||
|
||||
Reference in New Issue
Block a user