Update win_susp_copy_system32.yml

This commit is contained in:
Jonhnathan
2020-11-20 02:31:26 -03:00
committed by GitHub
parent 5d7131bbf2
commit ec1944e2d7
@@ -16,8 +16,10 @@ tags:
detection:
selection:
CommandLine|contains:
- ' /c copy *\System32\'
- 'xcopy*\System32\'
- ' /c copy'
- 'xcopy'
CommandLine|contains|all:
- '\System32\'
condition: selection
fields:
- CommandLine