Merge branch 'aurora-false-positive-fixing' of https://github.com/SigmaHQ/sigma into aurora-false-positive-fixing
This commit is contained in:
@@ -52,6 +52,7 @@ detection:
|
||||
- 'C:\Windows\System32\dllhost.exe'
|
||||
- 'C:\Windows\System32\DeviceCensus.exe'
|
||||
- 'C:\Windows\System32\MpSigStub.exe'
|
||||
- 'C:\Windows\UUS\amd64\MoUsoCoreWorker.exe'
|
||||
filter_system:
|
||||
Image: 'System'
|
||||
filter_Keybase:
|
||||
|
||||
Reference in New Issue
Block a user