Skip to content

Commit

Permalink
Update win_system_susp_service_installation_folder_pattern.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
nasbench committed Feb 26, 2024
1 parent 6236330 commit 92cc251
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ detection:
selection_eid:
Provider_Name: 'Service Control Manager'
EventID: 7045
suspicious_path:
selection_img_paths:
- ImagePath|re: '^[Cc]:\\[Pp]rogram[Dd]ata\\.{1,9}\.exe'
- ImagePath|re: '^[Cc]:\\.{1,9}\.exe'
condition: all of selection_*
Expand Down

0 comments on commit 92cc251

Please sign in to comment.