double quotes = escape

This commit is contained in:
juju4
2017-10-29 14:42:40 -04:00
parent 07185247cb
commit 4b64fc1704
@@ -15,7 +15,7 @@ detection:
- "*:\\RECYCLER\\*"
- "*:\\SystemVolumeInformation\\*"
- "%windir%\\Tasks\\*"
- "%systemroot%\debug\\*"
- "%systemroot%\\debug\\*"
condition: selection
falsepositives:
- False positives depend on scripts and administrative tools used in the monitored environment