@@ -16,9 +16,10 @@ detection:
|
||||
selection:
|
||||
EventID: 5861
|
||||
keywords:
|
||||
- 'ActiveScriptEventConsumer'
|
||||
- 'CommandLineEventConsumer'
|
||||
- 'CommandLineTemplate'
|
||||
Message:
|
||||
- '*ActiveScriptEventConsumer*'
|
||||
- '*CommandLineEventConsumer*'
|
||||
- '*CommandLineTemplate*'
|
||||
# - 'Binding EventFilter' # too many false positive with HP Health Driver
|
||||
selection2:
|
||||
EventID: 5859
|
||||
|
||||
Reference in New Issue
Block a user