Fix
This commit is contained in:
@@ -28,6 +28,8 @@ detection:
|
||||
# In some cases powershell was invoked with inverted slashes
|
||||
- '= C:/Windows/System32/WindowsPowerShell/v1.0/powershell'
|
||||
- '= C:/Windows/SysWOW64/WindowsPowerShell/v1.0/powershell'
|
||||
# When MSDT is launched
|
||||
- '= C:\WINDOWS\System32\sdiagnhost.exe -Embedding '
|
||||
filter_citrix:
|
||||
ContextInfo|contains: 'ConfigSyncRun.exe'
|
||||
filter_adace: # Active Directory Administrative Center Enhancements
|
||||
|
||||
Reference in New Issue
Block a user