We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 5baa0e7 commit 115cb99Copy full SHA for 115cb99
detections/T1093_Process_Hollowing.txt
@@ -55,7 +55,7 @@ Sysmon
55
)
56
) or (
57
process_path contains "userinit.exe" and (
58
- process_parent_command_line !contains "dwm.exe" or
+ process_parent_command_line !contains "dwm.exe" and
59
process_parent_command_line !contains "winlogon.exe"
60
61
0 commit comments