Skip to content

Commit

Permalink
Update proc_creation_win_driverquery_usage.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
nasbench committed Sep 29, 2023
1 parent f4dea12 commit db1e228
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ logsource:
category: process_creation
product: windows
detection:
selection_img:
selection:
- Image|endswith: 'driverquery.exe'
- OriginalFileName: 'drvqry.exe'
filter_main_other: # These are covered in 9fc3072c-dc8f-4bf7-b231-18950000fadd to avoid duplicate alerting
Expand Down

0 comments on commit db1e228

Please sign in to comment.