Update win_susp_sam_dump.yml
This commit is contained in:
@@ -15,8 +15,9 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 16
|
||||
Message|contains:
|
||||
- '\AppData\Local\Temp\SAM-*.dmp'
|
||||
Message|contains|all:
|
||||
- '\AppData\Local\Temp\SAM-'
|
||||
- '.dmp'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Penetration testing
|
||||
|
||||
Reference in New Issue
Block a user