Refined definition of defender executable
This commit is contained in:
@@ -63,7 +63,7 @@ detection:
|
||||
- C:\Windows\SysNative\
|
||||
- C:\Program Files\
|
||||
- C:\Windows\Temp\asgard2-agent\
|
||||
- C:\ProgramData\
|
||||
- C:\ProgramData\Microsoft\Windows Defender\Platform\
|
||||
filter2:
|
||||
ProcessName|startswith:
|
||||
- 'C:\Program Files' # too many false positives with legitimate AV and EDR solutions
|
||||
|
||||
Reference in New Issue
Block a user