fix: new FP with Avast
This commit is contained in:
@@ -6,7 +6,7 @@ status: experimental
|
||||
references:
|
||||
- https://twitter.com/SBousseaden/status/1483810148602814466
|
||||
date: 2022/01/20
|
||||
modified: 2022/10/27
|
||||
modified: 2022/10/28
|
||||
tags:
|
||||
- attack.execution
|
||||
logsource:
|
||||
@@ -72,7 +72,9 @@ detection:
|
||||
FileNameBuffer|endswith:
|
||||
- '\Program Files\Avast Software\Avast\aswAMSI.dll'
|
||||
- '\Program Files (x86)\Avast Software\Avast\aswAMSI.dll'
|
||||
ProcessNameBuffer|endswith: '\Windows\System32\SIHClient.exe'
|
||||
ProcessNameBuffer|endswith:
|
||||
- '\Windows\System32\SIHClient.exe'
|
||||
- '\Windows\System32\svchost.exe'
|
||||
RequestedPolicy: 12
|
||||
ValidatedPolicy: 1
|
||||
condition: selection and not 1 of filter_*
|
||||
|
||||
Reference in New Issue
Block a user