diff --git a/iocs/filename-iocs.txt b/iocs/filename-iocs.txt index 4262e9a..0d360ad 100644 --- a/iocs/filename-iocs.txt +++ b/iocs/filename-iocs.txt @@ -2152,7 +2152,7 @@ ystem32\\lcsvsvc\.dll;80 #\\hkcmd\.exe;60;(?i)\\(System32|system32|SYSTEM32|winsxs|WinSxS|SysWOW64|SysWow64|syswow64|SYSNATIVE)\\ #(?i)\\Mc\.exe;60;(?i)\\([Mm]icrosoft [Vv]isual [Ss]tudio|Windows Kits|Microsoft SDK|microsoft sdk) #(?i)\\MsMpEng\.exe;60;(?i)\\(Microsoft Security Client|Windows Defender|AntiMalware) -#(?i)\\msseces\.exe;60;(?i)\\Microsoft Security Center\\ +#(?i)\\msseces\.exe;60;(?i)\\(Microsoft Security Center|Microsoft Security Client)\\ #(?i)\\OInfoP11\.exe;60;(?i)(\\Common Files\\Microsoft Shared\\|\\Installer\\) #(?i)\\OleView\.exe;60;(?i)\\(Microsoft SDK|Windows Kits|[Mm]icrosoft [Vv]isual [Ss]tudio|Windows Resource Kit) #(?i)\\rc\.exe;60;(?i)\\(Microsoft SDK|Windows Kits|[Mm]icrosoft [Vv]isual [Ss]tudio|Windows Resocue Kit|[Mm]icrosoft.[Nn][Ee][Tt])