Skip to content

Commit

Permalink
fix: One value of imagePath was wrong
Browse files Browse the repository at this point in the history
it was "clip" that is already covered by "clipboard]::".

Real value is "&&" .

Reference: 
Sigma Rule Id: 4edf51e1-cb83-4e1a-bc39-800e396068e3
Link: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_invoke_obfuscation_clip_services_security.yml
  • Loading branch information
qasimqlf authored Feb 20, 2023
1 parent 848a64f commit 908b25b
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ references:
- https://github.com/SigmaHQ/sigma/issues/1009 #(Task 26)
author: Jonathan Cheong, oscd.community
date: 2020/10/13
modified: 2022/11/27
modified: 2023/02/20
tags:
- attack.defense_evasion
- attack.t1027
Expand All @@ -21,7 +21,7 @@ detection:
EventID: 7045
ImagePath|contains|all:
- 'cmd'
- 'clip'
- '&&'
- 'clipboard]::'
condition: selection
falsepositives:
Expand Down

0 comments on commit 908b25b

Please sign in to comment.