Update proc_creation_win_rundll32_parent_explorer.yml

This commit is contained in:
CD-R0M
2022-05-22 15:21:41 -04:00
parent 1e728d9598
commit e9976bc3db
@@ -12,6 +12,8 @@ detection:
selection:
Image|endswith: '\rundll32.exe'
ParentImage|endswith: '\explorer.exe'
filter:
CommandLine|contains: '\shell32.dll,OpenAs_RunDLL'
condition: selection
fields:
- Image