rule: updating csc.exe rule

This commit is contained in:
Florian Roth
2019-12-17 13:45:40 +01:00
parent 7a3041c593
commit c8b6b5c556
@@ -24,9 +24,11 @@ detection:
- '*\Windows\Temp\\*'
filter:
ParentImage:
- 'C:\Program Files*'
- '*\sdiagnhost.exe'
- 'C:\Program Files*' # https://twitter.com/gN3mes1s/status/1206874118282448897
- '*\sdiagnhost.exe' # https://twitter.com/gN3mes1s/status/1206874118282448897
- '*\w3wp.exe' # https://twitter.com/gabriele_pippi/status/1206907900268072962
condition: selection and not filter
falsepositives:
- Unkown
- https://twitter.com/gN3mes1s/status/1206874118282448897
- https://twitter.com/gabriele_pippi/status/1206907900268072962
level: high