Fix namefield.
This commit is contained in:
@@ -36,5 +36,5 @@ detection:
|
||||
selection:
|
||||
EventID: 4688
|
||||
CommandLine|re: '.*-[Vv][Ee][Rr][Ss][Ii][Oo][Nn] 2'
|
||||
Image|endswith: '\powershell.exe'
|
||||
NewProcessName|endswith: '\powershell.exe'
|
||||
condition: selection
|
||||
|
||||
Reference in New Issue
Block a user