16 lines
439 B
YAML
16 lines
439 B
YAML
title: Excluded Rule 2
|
|
date: 2021/11/18
|
|
detection:
|
|
condition: 'Cmdlet failed. Cmdlet Get-App, '
|
|
falsepositives:
|
|
- Unknown, please report false positives via https://github.com/SigmaHQ/sigma/issues
|
|
id: 00000000-0000-0000-0000-000000000000
|
|
level: critical
|
|
logsource:
|
|
product: windows
|
|
service: msexchange-management
|
|
references:
|
|
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321
|
|
status: experimental
|
|
ruletype: SIGMA
|