mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 10:13:57 +00:00
Update win_susp_explorer.yml
Added known-fp
This commit is contained in:
parent
85962665fd
commit
b147fc3296
@ -28,5 +28,5 @@ detection:
|
||||
- explorer.exe
|
||||
condition: selection1 or selection2
|
||||
falsepositives:
|
||||
- Unknown
|
||||
- Legitimate explorer.exe run from cmd.exe
|
||||
level: medium
|
||||
|
Loading…
Reference in New Issue
Block a user