Update win_susp_ntdsutil.yml

This commit is contained in:
Jonhnathan
2020-10-15 19:33:10 -03:00
committed by GitHub
parent ec9f9fd929
commit 98ebb4965d
@@ -15,7 +15,7 @@ logsource:
product: windows
detection:
selection:
CommandLine: '*\ntdsutil*'
CommandLine|contains: '\ntdsutil'
condition: selection
falsepositives:
- NTDS maintenance