Added the right System string to User filter

This commit is contained in:
Roberto Rodriguez
2021-10-27 01:22:19 -04:00
parent 9c7a736ca6
commit d80f73625f
@@ -22,8 +22,9 @@ detection:
ParentUser:
- 'NT AUTHORITY\NETWORK SERVICE'
- 'NT AUTHORITY\LOCAL SERVICE'
User:
- 'NT AUTHORITY\SYSTEM'
- 'AUTORITE NT\Sys' # French language settings
User: 'NT AUTHORITY\SYSTEM'
IntegrityLevel: 'System'
rundllexception:
Image|endswith: '\rundll32.exe'