refactor: any finding in spool drivers is relevant

This commit is contained in:
Florian Roth
2021-07-01 09:46:35 +02:00
committed by GitHub
parent 3382d5da09
commit a9500a3b1a
@@ -13,14 +13,9 @@ tag:
logsource:
product: antivirus
detection:
selection_path:
FileName|contains:
- 'C:\Windows\System32\spool\drivers\x64\'
selection_malware:
FileName|endswith:
- '.dll'
- '.exe'
condition: selection_path and selection_malware
selection:
FileName|contains: 'C:\Windows\System32\spool\drivers\x64\'
condition: selection
fields:
- Signature
- FileName