Skip to content

Commit a91720f

Browse files
committed
chore(rules): Exclude sysdir from Potential ClickFix infection chain rule
1 parent 7011d0b commit a91720f

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

rules/initial_access_potential_clickfix_infection_chain.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Potential ClickFix infection chain
22
id: ffe1fc54-2893-4760-ab50-51a83bd71d13
3-
version: 2.0.0
3+
version: 2.0.1
44
description: |
55
Identifies the execution of the process via the Run command dialog box, Windows Console shortuct, or Explorer address bar
66
followed by spawning of the potential infostealer process.
@@ -36,8 +36,7 @@ condition: >
3636
|spawn_process and ps.exe not imatches
3737
(
3838
'?:\\Program Files\\*.exe',
39-
'?:\\Program Files (x86)\\*.exe',
40-
'?:\\Windows\\System32\\*.exe'
39+
'?:\\Program Files (x86)\\*.exe'
4140
)
4241
| by ps.parent.uuid
4342
action:

0 commit comments

Comments
 (0)