Update sysmon_susp_driver_load.yml

This commit is contained in:
Jonhnathan 2020-11-19 22:56:34 -03:00 committed by GitHub
parent f42ef96140
commit 6ecafac619
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -14,7 +14,7 @@ logsource:
product: windows
detection:
selection:
ImageLoaded|contains: '\Temp\\'
ImageLoaded|contains: '\Temp\'
condition: selection
falsepositives:
- there is a relevant set of false positives depending on applications in the environment