Skip to content

Commit

Permalink
remove extra asterisk
Browse files Browse the repository at this point in the history
  • Loading branch information
YamatoSecurity committed Nov 10, 2023
1 parent 309c2de commit c303080
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ detection:
CommandLine|contains|all:
- 'sc query'
- 'ADManager Plus'
condition: 1 of selection_webserver_* and selection_anomaly_children and not 1 of filter_main_**
condition: 1 of selection_webserver_* and selection_anomaly_children and not 1 of filter_main_*
falsepositives:
- Particular web applications may spawn a shell process legitimately
level: high

0 comments on commit c303080

Please sign in to comment.