mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update cmd_carry_out_string_command_parameter.yml
This commit is contained in:
@@ -27,6 +27,7 @@ known_false_positives: False positives may be high based on legitimate scripted
|
||||
in any environment. Filter as needed.
|
||||
references:
|
||||
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- IcedID
|
||||
|
||||
Reference in New Issue
Block a user