Update sysmon_wmi_susp_scripting.yml
This commit is contained in:
@@ -17,17 +17,17 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 20
|
||||
Destination:
|
||||
- '*new-object system.net.webclient).downloadstring(*'
|
||||
- '*new-object system.net.webclient).downloadfile(*'
|
||||
- '*new-object net.webclient).downloadstring(*'
|
||||
- '*new-object net.webclient).downloadfile(*'
|
||||
- '* iex(*'
|
||||
- '*WScript.shell*'
|
||||
- '* -nop *'
|
||||
- '* -noprofile *'
|
||||
- '* -decode *'
|
||||
- '* -enc *'
|
||||
Destination|contains:
|
||||
- 'new-object system.net.webclient).downloadstring('
|
||||
- 'new-object system.net.webclient).downloadfile('
|
||||
- 'new-object net.webclient).downloadstring('
|
||||
- 'new-object net.webclient).downloadfile('
|
||||
- ' iex('
|
||||
- 'WScript.shell'
|
||||
- ' -nop '
|
||||
- ' -noprofile '
|
||||
- ' -decode '
|
||||
- ' -enc '
|
||||
condition: selection
|
||||
fields:
|
||||
- CommandLine
|
||||
|
||||
Reference in New Issue
Block a user