reworked rule
This commit is contained in:
+4
-4
@@ -15,10 +15,10 @@ logsource:
|
||||
detection:
|
||||
selection:
|
||||
EventID: 12 # MDE: ExploitGuardNonMicrosoftSignedBlocked
|
||||
ProcessPath|endswith:
|
||||
- '\MpCmdRun.exe'
|
||||
- '\NisSrv.exe'
|
||||
Image|endswith: '.dll'
|
||||
ProcessPath|endswith:
|
||||
- '\MpCmdRun.exe'
|
||||
- '\NisSrv.exe'
|
||||
ImageName|endswith: '.dll'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
|
||||
Reference in New Issue
Block a user