Merge pull request #800 from SanWieb/win_system_exe_anomaly

Extended Windows processes: win_system_exe_anomaly
This commit is contained in:
Florian Roth
2020-05-26 14:28:47 +02:00
committed by GitHub
@@ -30,6 +30,13 @@ detection:
- '*\winlogon.exe'
- '*\explorer.exe'
- '*\taskhost.exe'
- '*\Taskmgr.exe'
- '*\sihost.exe'
- '*\RuntimeBroker.exe'
- '*\smartscreen.exe'
- '*\dllhost.exe'
- '*\audiodg.exe'
- '*\wlanext.exe'
filter:
Image:
- 'C:\Windows\System32\\*'