Update win_susp_rundll32_by_ordinal.yml
This commit is contained in:
@@ -18,7 +18,8 @@ logsource:
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
CommandLine: '*\rundll32.exe *,#*'
|
||||
CommandLine|contains: '\rundll32.exe'
|
||||
CommandLine|contains: ',#'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
|
||||
Reference in New Issue
Block a user