Merge pull request #751 from zaphodef/fix/powershell_ntfs_ads_access

Add 'Add-Content' to powershell_ntfs_ads_access
This commit is contained in:
Florian Roth
2020-05-26 13:20:40 +02:00
committed by GitHub
@@ -16,6 +16,7 @@ logsource:
detection:
keyword1:
- "set-content"
- "add-content"
keyword2:
- "-stream"
condition: keyword1 and keyword2