Refined definition of defender executable

This commit is contained in:
stbe
2021-12-09 22:55:09 +01:00
parent 20f185f2b8
commit 44db55c4fd
@@ -63,7 +63,7 @@ detection:
- C:\Windows\SysNative\
- C:\Program Files\
- C:\Windows\Temp\asgard2-agent\
- C:\ProgramData\
- C:\ProgramData\Microsoft\Windows Defender\Platform\
filter2:
ProcessName|startswith:
- 'C:\Program Files' # too many false positives with legitimate AV and EDR solutions