Changed rule

* Adapted false positive notice to observation
* Decreased level
This commit is contained in:
Thomas Patzke 2019-05-09 23:25:23 +02:00
parent 3dd76a9c5e
commit e60fe1f46d

View File

@ -28,9 +28,9 @@ detection:
- '*\winlogon.exe'
filter:
ParentImage:
- '*\System32\*'
- '*\SysWOW64\*'
- '*\System32\\*'
- '*\SysWOW64\\*'
condition: selection and not filter
falsepositives:
- Unknown please report back
level: high
- Some security products seem to spawn these
level: low