mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
added false positive possibility
This commit is contained in:
parent
046510f021
commit
65e4ba5aba
@ -10,7 +10,7 @@ tags:
|
||||
- attack.defense_evasion
|
||||
detection:
|
||||
selection:
|
||||
CommandLine:
|
||||
CommandLine:
|
||||
- '*\msdt.exe*'
|
||||
- '*\installutil.exe*'
|
||||
- '*\regsvcs.exe*'
|
||||
@ -22,8 +22,9 @@ detection:
|
||||
# higher risk of false positives
|
||||
# - '*\cscript.EXE*'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
- Using installutil to add features for .NET applications (primarly would occur in developer environments)
|
||||
level: low
|
||||
---
|
||||
# Windows Audit Log
|
||||
|
Loading…
Reference in New Issue
Block a user