Update proc_creation_win_persistence_userinitmprlogonscript.yml
When logging into Windows Core, userinit.exe normalls calls PowerShell.exe without parameters to bring up a PowerShell window.
This commit is contained in:
+2
@@ -23,6 +23,8 @@ detection:
|
||||
- 'netlogon*.bat'
|
||||
- 'UsrLogon.cmd'
|
||||
- 'C:\WINDOWS\Explorer.EXE'
|
||||
- CommandLine:
|
||||
- 'PowerShell.exe'
|
||||
- Image|endswith:
|
||||
- '\explorer.exe'
|
||||
- '\proquota.exe'
|
||||
|
||||
Reference in New Issue
Block a user