Files
blue-team-tools/tests/test-base64offset-all.yml
T

10 lines
212 B
YAML

title: Testrule
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|base64offset|contains|all:
- foo
- bar
condition: selection