Add tagg Endswith

Prevent the trigger of {}.exe.log
This commit is contained in:
Sander Wiebing
2020-05-29 16:25:54 +02:00
committed by GitHub
parent 38afd8b5de
commit a00f7f19a1
@@ -15,7 +15,7 @@ logsource:
detection:
selection:
EventID: 11
TargetFilename:
TargetFilename|endswith:
- '*\svchost.exe'
- '*\rundll32.exe'
- '*\services.exe'