Merge pull request #751 from zaphodef/fix/powershell_ntfs_ads_access
Add 'Add-Content' to powershell_ntfs_ads_access
This commit is contained in:
@@ -16,6 +16,7 @@ logsource:
|
||||
detection:
|
||||
keyword1:
|
||||
- "set-content"
|
||||
- "add-content"
|
||||
keyword2:
|
||||
- "-stream"
|
||||
condition: keyword1 and keyword2
|
||||
|
||||
Reference in New Issue
Block a user