From 7037e77569e062b85f335ef3c9d04b2d392b5214 Mon Sep 17 00:00:00 2001 From: ecco Date: Mon, 25 May 2020 04:50:22 -0400 Subject: [PATCH] add more FP --- rules/windows/sysmon/sysmon_wmi_module_load.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/rules/windows/sysmon/sysmon_wmi_module_load.yml b/rules/windows/sysmon/sysmon_wmi_module_load.yml index 2c302532f..8c660f19e 100644 --- a/rules/windows/sysmon/sysmon_wmi_module_load.yml +++ b/rules/windows/sysmon/sysmon_wmi_module_load.yml @@ -34,6 +34,7 @@ detection: - '\DeviceCensus.exe' - '\CompatTelRunner.exe' - '\sdiagnhost.exe' + - '\SIHClient.exe' condition: selection and not filter fields: - ComputerName