update syntax to re-run the test once more...

This commit is contained in:
yugoslavskiy
2020-10-20 21:17:59 +02:00
committed by GitHub
parent 40f6d5e543
commit f050cedf92
@@ -16,8 +16,7 @@ logsource:
detection:
selection:
Image|endswith: '\regedit.exe'
CommandLine|contains:
- ' /E '
CommandLine|contains: ' /E '
filter_1: # filters to avoid intersection with critical keys rule
CommandLine|contains:
- 'hklm'