Enhanced to improve specificity
Enhanced to improve specificity per feedback received;
This commit is contained in:
@@ -16,9 +16,9 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
- '*\WerFault.exe'
|
||||
- '*\rundll32.exe'
|
||||
CommandLine|endswith:
|
||||
- '\WerFault.exe'
|
||||
- '\rundll32.exe'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unlikely
|
||||
|
||||
Reference in New Issue
Block a user