Adjusting condition

This commit is contained in:
Tim Shelton
2022-05-26 18:38:12 +00:00
parent 72e090b8c1
commit 5e2e776bce
@@ -39,7 +39,7 @@ detection:
- '\Windows\Tasks\'
- Image|startswith: 'C:\Perflogs\'
false_positive:
- Image|startswith: 'C:\Users\Public\IBM\ClientSolutions\Start_Programs\'
Image|startswith: 'C:\Users\Public\IBM\ClientSolutions\Start_Programs\'
condition: selection and not false_positive
fields:
- CommandLine