mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-08 18:23:52 +00:00
Update win_susp_explorer.yml
Added known-fp
This commit is contained in:
parent
85962665fd
commit
b147fc3296
@ -28,5 +28,5 @@ detection:
|
|||||||
- explorer.exe
|
- explorer.exe
|
||||||
condition: selection1 or selection2
|
condition: selection1 or selection2
|
||||||
falsepositives:
|
falsepositives:
|
||||||
- Unknown
|
- Legitimate explorer.exe run from cmd.exe
|
||||||
level: medium
|
level: medium
|
||||||
|
Loading…
Reference in New Issue
Block a user