Merge pull request #2230 from frack113/process_creation_clean

Process creation directory clean
This commit is contained in:
frack113
2021-11-08 21:27:25 +01:00
committed by GitHub
3 changed files with 2 additions and 2 deletions
@@ -6,7 +6,7 @@ references:
- https://twitter.com/subTee/status/1216465628946563073
- https://gist.github.com/am0nsec/8378da08f848424e4ab0cc5b317fdd26
date: 2020/01/13
modified: 2021/05/30
modified: 2021/11/06
author: Sreeman
tags:
- attack.defense_evasion
@@ -15,9 +15,9 @@ tags:
- attack.t1574.002
- attack.t1059 # an old one
- attack.t1064 # an old one
logsource:
product: windows
category: process_creation
detection:
selection1:
CommandLine|contains: