Update silenttrinity_stager_msbuild_activity.yml

This commit is contained in:
S.kiran kumar
2020-10-26 12:10:46 +05:30
committed by GitHub
parent 02ce1196c3
commit d7e9a87feb
@@ -14,10 +14,14 @@ logsource:
product: windows
detection:
selection:
ParentImage|endswith: '*\msbuild.exe'
condition: selection
fields:
- ParentImage
DestinationPort:
- '80'
- '443'
Initiated: 'true'
filter:
Image|endswith:
- '*\msbuild.exe'
condition: selection and not filter
falsepositives:
- unknown
level: high