double quotes = escape
This commit is contained in:
@@ -15,7 +15,7 @@ detection:
|
||||
- "*:\\RECYCLER\\*"
|
||||
- "*:\\SystemVolumeInformation\\*"
|
||||
- "%windir%\\Tasks\\*"
|
||||
- "%systemroot%\debug\\*"
|
||||
- "%systemroot%\\debug\\*"
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
|
||||
Reference in New Issue
Block a user