fixed missing os

This commit is contained in:
keyboardcrunch
2020-12-06 00:58:24 -06:00
parent bc3557a4ea
commit a7503f04a6
@@ -7,7 +7,7 @@ mitre:
tactic: Defense Evasion
technique: T1218
subtechnique: 011
operating_system:
operating_system: windows
query: ( SrcProcName In AnyCase ( "rundll32.exe" ) AND SrcProcCmdLine IS EMPTY ) OR ( SrcProcName In AnyCase ( "rundll32.exe" ) AND NetConnOutCount > "0" AND SrcProcParentName Not In ( "splwow64.exe" ) AND SrcProcParentName Not In ( "msiexec.exe" ) AND SrcProcCmdLine RegExp ".*((?!C:\\windows\\system32\\spool\\DRIVERS\\.*,MonitorPrintJobStatus))$/gmi" )
false_positives:
- Printer drivers