Update proc_creation_win_exfil_data_via_cli.yml

This commit is contained in:
Nasreddine Bencherchali
2022-08-04 10:58:56 +01:00
parent 8e08ff3060
commit 83451b3e6d
@@ -36,7 +36,7 @@ detection:
- ' -d ' # Shortest possible version of the --data flag
- ' --data '
payloads:
CommandLine|contains:
- CommandLine|contains:
- 'ToBase64String'
- 'whoami'
- 'nltest'
@@ -48,7 +48,7 @@ detection:
- 'systeminfo'
- 'tasklist'
- 'sc query'
CommandLine|contains|all:
- CommandLine|contains|all:
- 'type '
- ' > '
- ' C:\'