Skip to content

Commit

Permalink
Update image_load_malware_raspberry_robin_side_load_aclui_oleview.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
nasbench committed Aug 1, 2024
1 parent 083907f commit a3be253
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ detection:
Image|endswith: '\OleView.exe'
ImageLoaded|endswith: '\aclui.dll'
filter_main_legit_oleview_paths:
Image|contains:
Image|startswith:
- 'C:\Program Files (x86)\Windows Kits\'
- 'C:\Program Files\Microsoft SDKs\'
filter_optional_known_oleview_paths:
Expand Down

0 comments on commit a3be253

Please sign in to comment.