fix: FP with Code Integrity Attempted DLL Load
This commit is contained in:
@@ -77,6 +77,11 @@ detection:
|
||||
- '\Windows\System32\svchost.exe'
|
||||
RequestedPolicy: 12
|
||||
ValidatedPolicy: 1
|
||||
filter_gac:
|
||||
FileNameBuffer|endswith: '\stdole.dll'
|
||||
ProcessNameBuffer|endswith: '\mscorsvw.exe'
|
||||
RequestedPolicy: 8
|
||||
ValidatedPolicy: 2
|
||||
condition: selection and not 1 of filter_*
|
||||
falsepositives:
|
||||
- Unknown
|
||||
|
||||
Reference in New Issue
Block a user