Update win_renamed_psexec.yml
This commit is contained in:
@@ -20,9 +20,9 @@ detection:
|
||||
Description: 'Execute processes remotely'
|
||||
Product: 'Sysinternals PsExec'
|
||||
filter:
|
||||
Image:
|
||||
- '*\PsExec.exe'
|
||||
- '*\PsExec64.exe'
|
||||
Image|endswith:
|
||||
- '\PsExec.exe'
|
||||
- '\PsExec64.exe'
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
- Software that illegaly integrates PsExec in a renamed form
|
||||
|
||||
Reference in New Issue
Block a user