Add fp note to PortProxy rules
This commit is contained in:
@@ -21,5 +21,5 @@ detection:
|
||||
TargetObject: 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PortProxy\v4tov4\tcp'
|
||||
condition: selection_registry
|
||||
falsepositives:
|
||||
- Unlikely
|
||||
- WSL2 network bridge PowerShell script used for WSL/Kubernetes/Docker (e.g. https://github.com/microsoft/WSL/issues/4150#issuecomment-504209723)
|
||||
level: medium
|
||||
|
||||
Reference in New Issue
Block a user