Update win_file_winword_cve_2021_40444.yml
change TargetFilename|contains|all
This commit is contained in:
@@ -17,7 +17,7 @@ detection:
|
||||
TargetFilename|contains: '\Windows\INetCache'
|
||||
selection_inf:
|
||||
Image: '\winword.exe'
|
||||
TargetFilename|contains|all:
|
||||
TargetFilename|contains|all:
|
||||
- '\AppData\Local\Temp\'
|
||||
- '.inf'
|
||||
condition: selection or selection_inf
|
||||
|
||||
Reference in New Issue
Block a user