Added field names to first rules
This commit is contained in:
@@ -12,6 +12,9 @@ detection:
|
||||
- CommandLine: '*address=127.0.0.1*'
|
||||
- CommandLine: '*address=localhost*'
|
||||
condition: selection and not exclusion
|
||||
fields:
|
||||
- CommandLine
|
||||
- ParentCommandLine
|
||||
falsepositives:
|
||||
- unknown
|
||||
level: medium
|
||||
|
||||
Reference in New Issue
Block a user