rule: extended csc rule

This commit is contained in:
Florian Roth
2019-08-28 09:00:43 +02:00
parent 406b40af11
commit f71dc41531
@@ -15,7 +15,9 @@ logsource:
detection:
selection:
Image: '*\csc.exe'
CommandLine: '*\AppData\*'
CommandLine:
- '*\AppData\*'
- '*\Windows\Temp\*'
condition: selection
falsepositives:
- Unkown