Update sysmon_always_install_elevated_msi_spawned_cmd_and_powershell.yml
This commit is contained in:
+1
-2
@@ -23,9 +23,8 @@ detection:
|
||||
- 'msi'
|
||||
ParentImage|endswith:
|
||||
- 'tmp'
|
||||
condition: event_id and image and parent_image
|
||||
condition: image and parent_image
|
||||
fields:
|
||||
- EventID
|
||||
- Image
|
||||
- ParentImage
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user