Skip to content

Commit

Permalink
Merge PR #4553 from @qasimqlf - Add missing contains modifier
Browse files Browse the repository at this point in the history
update: Office Application Startup - Office Test - Add missing `contains` modifier
  • Loading branch information
qasimqlf authored Nov 8, 2023
1 parent 5d8c9a3 commit 67c323c
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ references:
- https://unit42.paloaltonetworks.com/unit42-technical-walkthrough-office-test-persistence-method-used-in-recent-sofacy-attacks/
author: omkar72
date: 2020/10/25
modified: 2023/09/28
modified: 2023/11/08
tags:
- attack.persistence
- attack.t1137.002
Expand All @@ -15,7 +15,7 @@ logsource:
product: windows
detection:
selection:
TargetObject: '\Software\Microsoft\Office test\Special\Perf'
TargetObject|contains: '\Software\Microsoft\Office test\Special\Perf'
condition: selection
falsepositives:
- Unlikely
Expand Down

0 comments on commit 67c323c

Please sign in to comment.