Fix namefield.

This commit is contained in:
Harish SEGAR
2020-03-20 23:34:15 +01:00
parent 67694e4ba7
commit a88b22a1bd
@@ -36,5 +36,5 @@ detection:
selection:
EventID: 4688
CommandLine|re: '.*-[Vv][Ee][Rr][Ss][Ii][Oo][Nn] 2'
Image|endswith: '\powershell.exe'
NewProcessName|endswith: '\powershell.exe'
condition: selection