Correct cast-sensitive Key "DestinationIp"

This commit is contained in:
frack113
2021-05-11 10:49:10 +02:00
parent 67e807983c
commit a1b0dfc0cd
@@ -6,7 +6,7 @@ references:
- https://twitter.com/SBousseaden/status/1096148422984384514
author: Samir Bousseaden
date: 2019/02/16
modified: 2020/08/24
modified: 2021/05/11
tags:
- attack.command_and_control
- attack.t1572
@@ -25,7 +25,7 @@ detection:
selection2:
- DestinationIp|startswith:
- '127.'
- DestinationIP:
- DestinationIp:
- '::1'
condition: selection and selection2
falsepositives: