mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update win_system_exe_anomaly.yml
fixing to much original fork.
This commit is contained in:
parent
7e7f6d1182
commit
f574c20432
@ -29,14 +29,14 @@ detection:
|
||||
- '*\lsm.exe'
|
||||
- '*\winlogon.exe'
|
||||
- '*\explorer.exe'
|
||||
- '*\taskhost.exe'
|
||||
- '*\taskhost.exe'
|
||||
filter:
|
||||
Image:
|
||||
- 'C:\Windows\System32\\*'
|
||||
- 'C:\Windows\SysWow64\\*'
|
||||
- 'C:\Windows\explorer.exe'
|
||||
- 'C:\Windows\winsxs\\*'
|
||||
- '\SystemRoot\System32\\*'
|
||||
- '\SystemRoot\System32\\*'
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
- Exotic software
|
||||
|
Loading…
Reference in New Issue
Block a user