Rule Windows 10 scheduled task SandboxEscaper 0-day

This commit is contained in:
Olaf Hartong
2019-05-22 12:32:07 +02:00
parent 544dfe3704
commit e675cdf9c4
@@ -11,7 +11,7 @@ logsource:
detection:
selection:
EventID: 1
Image: 'schtasks.exe'
Image: 'schtasks.exe'
CommandLine: '*/change*/TN*/RU*'
filter:
condition: selection