Update sysmon_always_install_elevated_msi_spawned_cmd_and_powershell.yml

This commit is contained in:
tas_kmanager
2020-10-16 09:30:20 -04:00
parent 23358b8db5
commit c4ddd56931
@@ -23,9 +23,8 @@ detection:
- 'msi'
ParentImage|endswith:
- 'tmp'
condition: event_id and image and parent_image
condition: image and parent_image
fields:
- EventID
- Image
- ParentImage
falsepositives: