fix: transformed rule to new proc_creation format
This commit is contained in:
+2
-3
@@ -25,10 +25,9 @@ detection:
|
||||
- '*mshta vbscript:Execute("Execute*'
|
||||
- '*mshta vbscript:CreateObject("Wscript.Shell").Run("mshta.exe*'
|
||||
selection2:
|
||||
EventID: 4688
|
||||
NewProcessName:
|
||||
Image:
|
||||
- 'C:\Windows\system32\mshta.exe'
|
||||
ProcessCommandLine:
|
||||
CommandLine:
|
||||
- '*.jpg*'
|
||||
- '*.png*'
|
||||
- '*.lnk*'
|
||||
Reference in New Issue
Block a user