fix: transformed rule to new proc_creation format

This commit is contained in:
Florian Roth
2019-03-12 09:03:30 +01:00
parent c4003ff410
commit 95b47972f0
@@ -25,10 +25,9 @@ detection:
- '*mshta vbscript:Execute("Execute*'
- '*mshta vbscript:CreateObject("Wscript.Shell").Run("mshta.exe*'
selection2:
EventID: 4688
NewProcessName:
Image:
- 'C:\Windows\system32\mshta.exe'
ProcessCommandLine:
CommandLine:
- '*.jpg*'
- '*.png*'
- '*.lnk*'