Correct cast-sensitive Key "DestinationIp"
This commit is contained in:
@@ -6,7 +6,7 @@ references:
|
||||
- https://twitter.com/SBousseaden/status/1096148422984384514
|
||||
author: Samir Bousseaden
|
||||
date: 2019/02/16
|
||||
modified: 2020/08/24
|
||||
modified: 2021/05/11
|
||||
tags:
|
||||
- attack.command_and_control
|
||||
- attack.t1572
|
||||
@@ -25,7 +25,7 @@ detection:
|
||||
selection2:
|
||||
- DestinationIp|startswith:
|
||||
- '127.'
|
||||
- DestinationIP:
|
||||
- DestinationIp:
|
||||
- '::1'
|
||||
condition: selection and selection2
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user