fix: value
This commit is contained in:
+2
-2
@@ -6,7 +6,7 @@ references:
|
||||
- https://cocomelonc.github.io/persistence/2022/12/09/malware-pers-20.html
|
||||
author: Tom Ueltschi (@c_APT_ure), Tim Shelton
|
||||
date: 2019/01/12
|
||||
modified: 2022/05/31
|
||||
modified: 2023/01/31
|
||||
tags:
|
||||
- attack.t1037.001
|
||||
- attack.persistence
|
||||
@@ -18,7 +18,7 @@ detection:
|
||||
ParentImage|endswith: '\userinit.exe'
|
||||
exec_exclusion1:
|
||||
Image|endswith:
|
||||
- 'explorer.exe'
|
||||
- '\explorer.exe'
|
||||
- '\proquota.exe'
|
||||
exec_exclusion2:
|
||||
CommandLine|contains:
|
||||
|
||||
Reference in New Issue
Block a user