Merge PR #4859 from @vburov - Update casing of Win32_ShadowCopy for multiple rules

chore: update casing of `Win32_ShadowCopy` for multiple rules

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
Vasiliy Burov
2024-05-27 15:33:46 +03:00
committed by GitHub
parent 4163fde77f
commit 92fd446b7d
6 changed files with 7 additions and 7 deletions
@@ -17,7 +17,7 @@ logsource:
detection:
selection:
ScriptBlockText|contains|all:
- win32_shadowcopy
- Win32_ShadowCopy
- ').Create('
- ClientAccessible
condition: selection
@@ -18,7 +18,7 @@ detection:
selection:
ScriptBlockText|contains|all:
- 'Get-WmiObject'
- 'Win32_Shadowcopy'
- 'Win32_ShadowCopy'
- '.Delete()'
condition: selection
falsepositives:
@@ -27,7 +27,7 @@ detection:
- 'Get-CimInstance'
- 'gcim'
selection_shadowcopy:
ScriptBlockText|contains: 'Win32_Shadowcopy'
ScriptBlockText|contains: 'Win32_ShadowCopy'
selection_delete:
ScriptBlockText|contains:
- '.Delete()'