Update proc_creation_win_lolbin_findstr.yml
This commit is contained in:
@@ -33,7 +33,7 @@ detection:
|
||||
CommandLine|contains:
|
||||
- /i
|
||||
- -i
|
||||
condition: selectionFindstr and (all of selection_cli_download* or all of selection_cli_creds*)
|
||||
condition: selectionFindstr and (all of selection_cli_download* or all of selection_cli_creds*)
|
||||
falsepositives:
|
||||
- Administrative findstr usage
|
||||
level: medium
|
||||
|
||||
Reference in New Issue
Block a user