Update sysmon_quarkspw_filedump.yml

This commit is contained in:
Jonhnathan
2020-10-15 16:01:24 -03:00
committed by GitHub
parent d2d49c445a
commit 9eedeabda9
@@ -18,7 +18,7 @@ logsource:
detection:
selection:
# Sysmon: File Creation (ID 11)
TargetFilename: '*\AppData\Local\Temp\SAM-*.dmp*'
TargetFilename|contains: '\AppData\Local\Temp\SAM-*.dmp'
condition: selection
falsepositives:
- Unknown