fix: value

This commit is contained in:
Qasim Qlf
2023-01-31 12:25:32 +05:00
committed by GitHub
parent 9e51af56ca
commit e1913adfc5
@@ -6,7 +6,7 @@ references:
- https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html
author: Tom Ueltschi (@c_APT_ure), Tim Shelton
date: 2019/01/12
modified: 2022/05/31
modified: 2023/01/31
tags:
- attack.t1037.001
- attack.persistence
@@ -18,7 +18,7 @@ detection:
ParentImage|endswith: '\userinit.exe'
exec_exclusion1:
Image|endswith:
- 'explorer.exe'
- '\explorer.exe'
- '\proquota.exe'
exec_exclusion2:
CommandLine|contains: