Update proc_creation_win_renamed_procdump.yml
This commit is contained in:
@@ -31,7 +31,7 @@ detection:
|
||||
Image|endswith:
|
||||
- '\procdump.exe'
|
||||
- '\procdump64.exe'
|
||||
condition: (original_file_name or all of selection_*) and not filter
|
||||
condition: original_file_name or all of selection_* and not filter
|
||||
falsepositives:
|
||||
- Procdump illegaly bundled with legitimate software
|
||||
- Weird admins who renamed binaries (and should be investigated)
|
||||
|
||||
Reference in New Issue
Block a user