Logic fix for sysmon_non_priv_program_files_move

This commit is contained in:
Ryan Plas
2020-11-10 10:01:47 -05:00
parent 782a55b8e5
commit d4d694b4da
@@ -21,10 +21,11 @@ detection:
- TargetFilename|contains:
- '\Program Files\'
- '\Program Files (x86)\'
- TargetFilename|startswith: '\Windows\'
windows:
TargetFilename|startswith: '\Windows\'
temp:
TargetFilename|contains: 'temp'
condition: integrity and (program_files or temp)
condition: integrity and (program_files or windows and not temp)
falsepositives:
- Unknown
level: medium