Update win_apt_mustangpanda.yml
This commit is contained in:
@@ -13,12 +13,13 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection1:
|
||||
CommandLine:
|
||||
- '*Temp\wtask.exe /create*'
|
||||
- '*%windir:~-3,1%%PUBLIC:~-9,1%*'
|
||||
- '*/E:vbscript * C:\Users\\*.txt" /F'
|
||||
- '*/tn "Security Script *'
|
||||
- '*%windir:~-1,1%*'
|
||||
CommandLine|endswith:
|
||||
- 'Temp\wtask.exe /create*'
|
||||
- '%windir:~-3,1%%PUBLIC:~-9,1%*'
|
||||
- '/tn "Security Script *'
|
||||
- '%windir:~-1,1%*'
|
||||
Commandline|startswith:
|
||||
- '/E:vbscript * C:\Users\\*.txt" /F'
|
||||
selection2:
|
||||
Image:
|
||||
- '*Temp\winwsh.exe'
|
||||
|
||||
Reference in New Issue
Block a user