fix: FPs noticed with Aurora
This commit is contained in:
@@ -68,6 +68,8 @@ detection:
|
||||
- 'C:\WINDOWS\system32\NhNotifSys.exe'
|
||||
- TargetImage:
|
||||
- 'C:\Windows\System32\RuntimeBroker.exe'
|
||||
- TargetImage|endswith:
|
||||
- '\Microsoft VS Code\Code.exe'
|
||||
- CallTrace|contains: # attempt to save the rule with a broader filter
|
||||
- '|C:\WINDOWS\System32\RPCRT4.dll+'
|
||||
filter_set_1:
|
||||
|
||||
Reference in New Issue
Block a user