Enhanced to improve specificity

Enhanced to improve specificity per feedback received;
This commit is contained in:
invrep-de
2020-10-26 12:05:16 -04:00
committed by GitHub
parent 7b49a4690e
commit 8a9db12d30
@@ -16,9 +16,9 @@ logsource:
product: windows
detection:
selection:
CommandLine:
- '*\WerFault.exe'
- '*\rundll32.exe'
CommandLine|endswith:
- '\WerFault.exe'
- '\rundll32.exe'
condition: selection
falsepositives:
- Unlikely