Skip to content

Commit

Permalink
Update win_susp_service_installation_script.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 authored Mar 24, 2022
1 parent 76710a1 commit 37437c7
Showing 1 changed file with 4 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,15 @@ detection:
Provider_Name: 'Service Control Manager'
EventID: 7045
suspicious1:
- ImagePath|contains: ' /C '
- ImagePath|contains:
ImagePath|contains: ' /C '
suspicious2:
ImagePath|contains:
- 'powershell'
- 'wscript'
- 'cscript'
- 'mshta'
- 'rundll32'
condition: selection and 1 of suspicious*
condition: selection and all of suspicious*
falsepositives:
- Unknown
level: high
Expand Down

0 comments on commit 37437c7

Please sign in to comment.