Skip to content

Commit 5860f66

Browse files
committed
chore(rules): Reorder not operators
Make sure the not operator is placed after the field.
1 parent 611bd14 commit 5860f66

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

rules/defense_evasion_dll_sideloading_via_copied_binary.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ labels:
2020
condition: >
2121
sequence
2222
maxspan 8m
23-
|create_file and file.is_exec and not ps.sid in ('S-1-5-18', 'S-1-5-19', 'S-1-5-20')
23+
|create_file and file.is_exec and ps.sid not in ('S-1-5-18', 'S-1-5-19', 'S-1-5-20')
2424
and
2525
thread.callstack.symbols imatches ('*CopyFile*', '*MoveFile*')
2626
| by file.name

rules/defense_evasion_potential_process_hollowing_injection.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ references:
2929
condition: >
3030
sequence
3131
maxspan 2m
32-
|spawn_process and not ps.sid in ('S-1-5-18', 'S-1-5-19', 'S-1-5-20') and not ps.exe imatches
32+
|spawn_process and ps.sid not in ('S-1-5-18', 'S-1-5-19', 'S-1-5-20') and not ps.exe imatches
3333
(
3434
'?:\\Program Files\\*',
3535
'?:\\Program Files (x86)\\*'

0 commit comments

Comments
 (0)