Update proc_creation_win_susp_runonce_execution.yml

This commit is contained in:
securepeacock
2022-12-13 10:27:21 -05:00
committed by GitHub
parent ad55efd25f
commit af3857b42f
@@ -24,8 +24,7 @@ detection:
- '/AlternateShellStartup'
- '/r'
filter:
CommandLine|contains:
- '/Run6432'
CommandLine|contains: '/Run6432'
condition: all of selection* and not filter
falsepositives:
- Unknown