add keywords condition

This commit is contained in:
frack113
2021-08-17 06:24:04 +02:00
committed by GitHub
parent 32fc191163
commit e098fc73cb
+8 -1
View File
@@ -19,7 +19,14 @@ detection:
- 'schema=Reset'
- 'VirtualDirectory'
cs-username|endswith: '$'
condition: selection
keywords:
- 'POST'
- '200'
- '/ecp/DDI/DDIService.svc/SetObject'
- 'schema=Reset'
- 'VirtualDirectory'
- '$'
condition: selection or all of keywords
falsepositives:
- Unlikely
level: critical