Update win_susp_msmpeng_crash.yml

This commit is contained in:
Jonhnathan 2020-10-15 15:50:01 -03:00 committed by GitHub
parent c310d72e2b
commit 9b8817f489
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -23,9 +23,9 @@ detection:
Source: 'Windows Error Reporting'
EventID: 1001
keywords:
Message:
- '*MsMpEng.exe*'
- '*mpengine.dll*'
Message|contains:
- 'MsMpEng.exe'
- 'mpengine.dll'
condition: 1 of selection* and all of keywords
falsepositives:
- MsMpEng.exe can crash when C:\ is full