mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Changed rule
* Adapted false positive notice to observation * Decreased level
This commit is contained in:
parent
3dd76a9c5e
commit
e60fe1f46d
@ -28,9 +28,9 @@ detection:
|
||||
- '*\winlogon.exe'
|
||||
filter:
|
||||
ParentImage:
|
||||
- '*\System32\*'
|
||||
- '*\SysWOW64\*'
|
||||
- '*\System32\\*'
|
||||
- '*\SysWOW64\\*'
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
- Unknown please report back
|
||||
level: high
|
||||
- Some security products seem to spawn these
|
||||
level: low
|
Loading…
Reference in New Issue
Block a user