Update win_susp_sam_dump.yml

This commit is contained in:
Jonhnathan
2020-10-27 22:01:31 -03:00
committed by GitHub
parent 61ccdc598d
commit dde5b46726
+3 -2
View File
@@ -15,8 +15,9 @@ logsource:
detection:
selection:
EventID: 16
Message|contains:
- '\AppData\Local\Temp\SAM-*.dmp'
Message|contains|all:
- '\AppData\Local\Temp\SAM-'
- '.dmp'
condition: selection
falsepositives:
- Penetration testing