Fix ProcessCommandLine field

This commit is contained in:
Cedric HIEN
2021-03-15 11:56:19 +01:00
parent 310888bae7
commit e4f24f4e1f
@@ -16,7 +16,7 @@ logsource:
service: process_creation
detection:
selection:
ProcessCommandline|contains|all:
ProcessCommandLine|contains|all:
- '/UpdateDeploymentProvider'
- '/RunHandlerComServer'
Image|endswith:
@@ -24,4 +24,4 @@ detection:
condition: selection
falsepositives:
- Unknown
level: high
level: high