Adjusting condition
This commit is contained in:
@@ -39,7 +39,7 @@ detection:
|
||||
- '\Windows\Tasks\'
|
||||
- Image|startswith: 'C:\Perflogs\'
|
||||
false_positive:
|
||||
- Image|startswith: 'C:\Users\Public\IBM\ClientSolutions\Start_Programs\'
|
||||
Image|startswith: 'C:\Users\Public\IBM\ClientSolutions\Start_Programs\'
|
||||
condition: selection and not false_positive
|
||||
fields:
|
||||
- CommandLine
|
||||
|
||||
Reference in New Issue
Block a user