sigma
sigma copied to clipboard
Update win_impacket_psexec.yml
Based on recent tests, the original RelativeTargetName from this rule are not accurate. The last "t" from each selection must be deleted in order to detect the predefined impacket psexec behavior.
Hi ,
Good catch
modified must be update to 2022/09/18
contains can be change to endswith as the parttern is " *-stdin or *-stdout or *-stderr"