Skip to content

Commit 115cb99

Browse files
Update T1093_Process_Hollowing.txt
"and" instead of "or"
1 parent 5baa0e7 commit 115cb99

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/T1093_Process_Hollowing.txt

+1-1
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ Sysmon
5555
)
5656
) or (
5757
process_path contains "userinit.exe" and (
58-
process_parent_command_line !contains "dwm.exe" or
58+
process_parent_command_line !contains "dwm.exe" and
5959
process_parent_command_line !contains "winlogon.exe"
6060
)
6161
)

0 commit comments

Comments
 (0)