fix: new FP with Avast

This commit is contained in:
phantinuss
2022-10-28 08:47:01 +02:00
parent 625f05df3c
commit f7319989e4
@@ -6,7 +6,7 @@ status: experimental
references:
- https://twitter.com/SBousseaden/status/1483810148602814466
date: 2022/01/20
modified: 2022/10/27
modified: 2022/10/28
tags:
- attack.execution
logsource:
@@ -72,7 +72,9 @@ detection:
FileNameBuffer|endswith:
- '\Program Files\Avast Software\Avast\aswAMSI.dll'
- '\Program Files (x86)\Avast Software\Avast\aswAMSI.dll'
ProcessNameBuffer|endswith: '\Windows\System32\SIHClient.exe'
ProcessNameBuffer|endswith:
- '\Windows\System32\SIHClient.exe'
- '\Windows\System32\svchost.exe'
RequestedPolicy: 12
ValidatedPolicy: 1
condition: selection and not 1 of filter_*