Update condition to filter out printer port

This commit is contained in:
Tran Trung Hieu
2020-05-14 18:22:49 +07:00
parent 443bf09d27
commit e53a97fa2f
@@ -18,8 +18,8 @@ detection:
EventID: 3
Image: '*\notepad.exe'
filter:
DestinationPort: 9100
condition: selection
DestinationPort: '9100'
condition: selection and not filter
falsepositives:
- None observed so far
level: high