Update proc_creation_win_susp_runonce_execution.yml
This commit is contained in:
@@ -24,8 +24,7 @@ detection:
|
||||
- '/AlternateShellStartup'
|
||||
- '/r'
|
||||
filter:
|
||||
CommandLine|contains:
|
||||
- '/Run6432'
|
||||
CommandLine|contains: '/Run6432'
|
||||
condition: all of selection* and not filter
|
||||
falsepositives:
|
||||
- Unknown
|
||||
|
||||
Reference in New Issue
Block a user