Update proc_creation_win_powershell_amsi_bypass.yml

This commit is contained in:
Nasreddine Bencherchali
2022-09-02 12:02:18 +02:00
parent 37f08c4cbb
commit 884891746b
@@ -12,7 +12,7 @@ logsource:
category: process_creation
product: windows
detection:
selection1:
selection:
CommandLine|contains:
- 'System.Management.Automation.AmsiUtils'
- 'amsiInitFailed'