Files
hayabusa/test_files/rules/yaml/exclude2.yml
DustInDark 91a89a42ad fixed test
2022-06-22 00:21:58 +09:00

16 lines
439 B
YAML

title: Excluded Rule 2
date: 2021/11/18
detection:
condition: 'Cmdlet failed. Cmdlet Get-App, '
falsepositives:
- Unknown, please report false positives via https://github.com/SigmaHQ/sigma/issues
id: 00000000-0000-0000-0000-000000000000
level: critical
logsource:
product: windows
service: msexchange-management
references:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42321
status: experimental
ruletype: SIGMA