Skip to content

Commit 78071f6

Browse files
authored
Merge branch 'develop' into github_detections_improvement
2 parents 77cbb83 + 23838ed commit 78071f6

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

detections/endpoint/suspicious_copy_on_system32.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Suspicious Copy on System32
22
id: ce633e56-25b2-11ec-9e76-acde48001122
3-
version: 6
4-
date: '2025-02-10'
3+
version: 7
4+
date: '2025-02-21'
55
author: Teoderick Contreras, Splunk
66
status: production
77
type: TTP
@@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
2323
AND `process_copy` AND Processes.process IN("*\\Windows\\System32\\*", "*\\Windows\\SysWow64\\*")
2424
AND Processes.process = "*copy*" by Processes.dest Processes.user Processes.parent_process_name
2525
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
26-
temp | `drop_dm_object_name(Processes)` | eval splitted_commandline=split(process,"
26+
| `drop_dm_object_name(Processes)` | eval splitted_commandline=split(process,"
2727
") | eval first_cmdline=lower(mvindex(splitted_commandline,0)) | where NOT LIKE(first_cmdline,"%\\windows\\system32\\%")
2828
AND NOT LIKE(first_cmdline,"%\\windows\\syswow64\\%") | `security_content_ctime(firstTime)`
2929
| `security_content_ctime(lastTime)` |`suspicious_copy_on_system32_filter`'

0 commit comments

Comments
 (0)