Added the right System string to User filter
This commit is contained in:
@@ -22,8 +22,9 @@ detection:
|
||||
ParentUser:
|
||||
- 'NT AUTHORITY\NETWORK SERVICE'
|
||||
- 'NT AUTHORITY\LOCAL SERVICE'
|
||||
User:
|
||||
- 'NT AUTHORITY\SYSTEM'
|
||||
- 'AUTORITE NT\Sys' # French language settings
|
||||
User: 'NT AUTHORITY\SYSTEM'
|
||||
IntegrityLevel: 'System'
|
||||
rundllexception:
|
||||
Image|endswith: '\rundll32.exe'
|
||||
|
||||
Reference in New Issue
Block a user