Update win_susp_explorer.yml

Added known-fp
This commit is contained in:
Furkan ÇALIŞKAN 2020-10-05 13:22:43 +03:00 committed by GitHub
parent 85962665fd
commit b147fc3296
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -28,5 +28,5 @@ detection:
- explorer.exe - explorer.exe
condition: selection1 or selection2 condition: selection1 or selection2
falsepositives: falsepositives:
- Unknown - Legitimate explorer.exe run from cmd.exe
level: medium level: medium