Update win_mal_ursnif.yml

This commit is contained in:
Jonhnathan
2020-10-15 16:18:38 -03:00
committed by GitHub
parent 983e9cb9ae
commit acfe0633e2
+1 -1
View File
@@ -16,7 +16,7 @@ logsource:
detection:
selection:
EventID: 13
TargetObject: '*\Software\AppDataLow\Software\Microsoft\\*'
TargetObject|contains: '\Software\AppDataLow\Software\Microsoft\\'
condition: selection
falsepositives:
- Unknown