docs: rules adjusted

This commit is contained in:
Florian Roth
2022-06-21 17:21:55 +02:00
parent 3f189e52c1
commit c2c25acbb6
2 changed files with 3 additions and 3 deletions
@@ -29,4 +29,4 @@ detection:
condition: selection and not filter
falsepositives:
- Unknown
level: medium
level: low
@@ -1,9 +1,9 @@
title: Suspicious Characters in CommandLine
id: 2c0d2d7b-30d6-4d14-9751-7b9113042ab9
status: experimental
description: Detects suspicious characters in the command line, which could be a sign of obfuscation
description: Detects suspicious Unicode characters in the command line, which could be a sign of obfuscation or defense evasion
date: 2022/04/27
author: 'Florian Roth'
author: Florian Roth
references:
- https://www.wietzebeukema.nl/blog/windows-command-line-obfuscation
logsource: