Update win_susp_rundll32_by_ordinal.yml

This commit is contained in:
Jonhnathan
2020-10-15 19:46:54 -03:00
committed by GitHub
parent 8d471775e0
commit d3f0d25ffb
@@ -18,7 +18,8 @@ logsource:
product: windows
detection:
selection:
CommandLine: '*\rundll32.exe *,#*'
CommandLine|contains: '\rundll32.exe'
CommandLine|contains: ',#'
condition: selection
falsepositives:
- False positives depend on scripts and administrative tools used in the monitored environment