Skip to content

Commit

Permalink
added expand modifier to placeholder rule
Browse files Browse the repository at this point in the history
  • Loading branch information
YamatoSecurity committed Aug 1, 2024
1 parent b8e67f1 commit b9bf675
Showing 1 changed file with 2 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -15,9 +15,8 @@ logsource:
product: windows
detection:
selection:
CommandLine|contains|all:
- 'echo '
- '%userdomain%'
CommandLine|contains: 'echo '
CommandLine|contains|expand: '%userdomain%'
condition: selection
falsepositives:
- Certain scripts or applications may leverage this.
Expand Down

0 comments on commit b9bf675

Please sign in to comment.