Merge pull request #323 from Karneades/filterFix
Restrict filter in system exe anomaly rule
This commit is contained in:
@@ -26,8 +26,8 @@ detection:
|
||||
- '*\conhost.exe'
|
||||
filter:
|
||||
Image:
|
||||
- '*\System32\\*'
|
||||
- '*\SysWow64\\*'
|
||||
- 'C:\Windows\System32\\*'
|
||||
- 'C:\Windows\SysWow64\\*'
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
- Exotic software
|
||||
|
||||
Reference in New Issue
Block a user