olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.13k stars 177 forks source link

Fixed syntax for "process_command_line" with "sc" #11

Closed bmk666 closed 5 years ago

bmk666 commented 5 years ago

changed:

process_command_line="sc to process_command_line="*sc\