Files
blue-team-tools/tests/test-windash-all.yml
T
2022-05-02 00:38:21 +02:00

10 lines
229 B
YAML

title: Testrule
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|windash|contains|all:
- -foo-1 -bar-2 -bla-3
- -foo-bar
condition: selection