Update sysmon_susp_office_dotnet_assembly_dll_load.yml
This commit is contained in:
@@ -16,10 +16,10 @@ detection:
|
||||
selection:
|
||||
EventID: 7
|
||||
Image:
|
||||
- '*winword.exe*'
|
||||
- '*powerpnt.exe*'
|
||||
- '*excel.exe*'
|
||||
- '*outlook.exe*'
|
||||
- '*\winword.exe*'
|
||||
- '*\powerpnt.exe*'
|
||||
- '*\excel.exe*'
|
||||
- '*\outlook.exe*'
|
||||
ImageLoaded:
|
||||
- '*C:\Windows\assembly\*'
|
||||
condition: selection
|
||||
|
||||
Reference in New Issue
Block a user