Update win_bypass_squiblytwo.yml

This commit is contained in:
Jonhnathan
2020-11-26 23:33:00 -03:00
committed by GitHub
parent d5803b89ef
commit a403082631
@@ -24,8 +24,8 @@ logsource:
product: windows
detection:
selection1:
Image:
- '*\wmic.exe'
Image|endswith:
- '\wmic.exe'
CommandLine|contains|all:
- wmic
- format