Merge pull request #3983 from qasimqlf/patch-24

fix: value
This commit is contained in:
frack113
2023-01-31 13:50:02 +01:00
committed by GitHub
@@ -6,6 +6,7 @@ references:
- https://lolbas-project.github.io/lolbas/Binaries/Pktmon/
author: frack113
date: 2022/03/17
modified: 2023/01/31
tags:
- attack.credential_access
- attack.t1040
@@ -14,7 +15,7 @@ logsource:
product: windows
detection:
selection:
- Image|endswith: 'PktMon.exe'
- Image|endswith: '\pktmon.exe'
- OriginalFileName: 'PktMon.exe'
condition: selection
falsepositives: