I expect to detect Plugx malware with the following behavior: - Load a dll file in the same directory - Reads a .dat file in the same directory How can I write rules with AND conditions. I tried with the rules below, but it just seems to understand that this is an OR condition.
I am afraid that may not be possible at the moment using Expert rules. This may go as a product enhancement request, however, this currently works very similar to Access Protection on Endpoint Security that also does not implement "AND" conditions between rules or even among subrules and only works on "OR" basis.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.