Update win_susp_ping_hex_ip.yml

This commit is contained in:
Jonhnathan
2020-10-15 19:34:00 -03:00
committed by GitHub
parent 6bb9f1b3c9
commit 90d20094ac
@@ -15,9 +15,9 @@ logsource:
product: windows
detection:
selection:
CommandLine:
- '*\ping.exe 0x*'
- '*\ping 0x*'
CommandLine|contains:
- '\ping.exe 0x'
- '\ping 0x'
condition: selection
fields:
- ParentCommandLine