Update win_susp_sdelete.yml
This commit is contained in:
@@ -28,9 +28,9 @@ detection:
|
||||
- 4656
|
||||
- 4663
|
||||
- 4658
|
||||
ObjectName:
|
||||
- '*.AAA'
|
||||
- '*.ZZZ'
|
||||
ObjectName|endswith:
|
||||
- '.AAA'
|
||||
- '.ZZZ'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Legitime usage of SDelete
|
||||
|
||||
Reference in New Issue
Block a user