Skip to content

Commit

Permalink
Deleted EventID part
Browse files Browse the repository at this point in the history
  • Loading branch information
caliskanfurkan authored Jun 4, 2020
1 parent 1c677aa commit 0744107
Showing 1 changed file with 0 additions and 1 deletion.
1 change: 0 additions & 1 deletion rules/windows/sysmon/sysmon_apt_muddywater_dnstunnel.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,6 @@ logsource:
product: windows
detection:
selection:
EventID: 1
Image|endswith:
- '\powershell.exe'
ParentImage|endswith:
Expand Down

0 comments on commit 0744107

Please sign in to comment.