Completed requested changes
selection2:
Image|endswith:
This commit is contained in:
+1
-1
@@ -22,7 +22,7 @@ detection:
|
||||
EventType: WMIExecution
|
||||
WMIcommand|contains: 'Win32_Process\:\:Create'
|
||||
selection2:
|
||||
- Image|endswith:
|
||||
Image|endswith:
|
||||
- '\winword.exe'
|
||||
- '\excel.exe'
|
||||
- '\powerpnt.exe'
|
||||
|
||||
Reference in New Issue
Block a user