Extended Windows processes

This commit is contained in:
Sander Wiebing
2020-05-26 13:56:51 +02:00
committed by GitHub
parent f9f814f3b3
commit 3681b8cb56
@@ -30,6 +30,13 @@ detection:
- '*\winlogon.exe'
- '*\explorer.exe'
- '*\taskhost.exe'
- '*\Taskmgr.exe'
- '*\sihost.exe'
- '*\RuntimeBroker.exe'
- '*\smartscreen.exe'
- '*\dllhost.exe'
- '*\audiodg.exe'
- '*\wlanext.exe'
filter:
Image:
- 'C:\Windows\System32\\*'