Extended Windows processes
This commit is contained in:
@@ -30,6 +30,13 @@ detection:
|
||||
- '*\winlogon.exe'
|
||||
- '*\explorer.exe'
|
||||
- '*\taskhost.exe'
|
||||
- '*\Taskmgr.exe'
|
||||
- '*\sihost.exe'
|
||||
- '*\RuntimeBroker.exe'
|
||||
- '*\smartscreen.exe'
|
||||
- '*\dllhost.exe'
|
||||
- '*\audiodg.exe'
|
||||
- '*\wlanext.exe'
|
||||
filter:
|
||||
Image:
|
||||
- 'C:\Windows\System32\\*'
|
||||
|
||||
Reference in New Issue
Block a user