fix: Msiexec FPs noticed with Aurora

This commit is contained in:
Florian Roth
2022-09-03 09:30:24 +02:00
parent 6a6454cda9
commit c7eddebe40
@@ -6,7 +6,7 @@ author: Nasreddine Bencherchali
references:
- https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC (Idea)
date: 2022/07/17
modified: 2022/08/10
modified: 2022/09/03
logsource:
product: windows
category: image_load
@@ -21,7 +21,8 @@ detection:
- '\AppData\Local\Temp\'
- 'C:\PerfLogs\'
filter:
ImageLoaded|contains: '\Program Files'
- ImageLoaded|contains: '\Program Files'
- Image|endswith: '\msiexec.exe'
condition: selection and not filter
falsepositives:
- Unknown