fix: fp with iissetup
This commit is contained in:
@@ -25,6 +25,8 @@ detection:
|
||||
CommandLine|contains:
|
||||
- '/name:'
|
||||
- '-name:'
|
||||
filter_iis_setup:
|
||||
ParentImage: 'C:\Windows\System32\inetsrv\iissetup.exe'
|
||||
condition: all of selection_*
|
||||
falsepositives:
|
||||
- Unknown as it may vary from organisation to organisation how admins use to install IIS modules
|
||||
|
||||
Reference in New Issue
Block a user