Update win_susp_security_eventlog_cleared.yml
This commit is contained in:
@@ -12,7 +12,6 @@ detection:
|
||||
EventID:
|
||||
- 517
|
||||
- 1102
|
||||
- 104
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Rollout of log collection agents (the setup routine often includes a reset of the local Eventlog)
|
||||
|
||||
Reference in New Issue
Block a user