We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent f930b52 commit 7217019Copy full SHA for 7217019
detections/endpoint/windows_dll_side_loading_in_calc.yml
@@ -42,7 +42,7 @@ drilldown_searches:
42
earliest_offset: $info_min_time$
43
latest_offset: $info_max_time$
44
rba:
45
- message: The [ $image$ ] process loaded the [ $ImageLoaded$ ] DLL from a non-standard location on [ $dest$ ]
+ message: The [ $Image$ ] process loaded the [ $ImageLoaded$ ] DLL from a non-standard location on [ $dest$ ]
46
risk_objects:
47
- field: dest
48
type: system
0 commit comments