Update win_susp_multiple_files_renamed_or_deleted.yml

This commit is contained in:
Vasiliy Burov 2020-10-28 11:44:21 +03:00 committed by GitHub
parent 744c637125
commit d90ec67cce
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -22,5 +22,6 @@ detection:
timeframe: 30s
condition: selection | count() by SubjectLogonId > 10
falsepositives:
- Unlikely
- Software uninstallation
- Files restore activities
level: high