Update image_load_msdt_sdiageng.yml

This commit is contained in:
Florian Roth
2022-06-17 18:46:14 +02:00
committed by GitHub
parent 725cadc902
commit fda9c753e2
@@ -13,7 +13,7 @@ detection:
selection_img:
Image|endswith: '\msdt.exe'
selection_load:
ImageLoaded|endswith: 'sdiageng.dll'
ImageLoaded|endswith: '\sdiageng.dll'
condition: all of selection*
falsepositives:
- Unknown