Fix falsepositives list

This commit is contained in:
frack113
2021-05-21 12:29:28 +02:00
parent ad376a8328
commit a6cadc6de5
@@ -4,6 +4,7 @@ description: Detects Execution via SyncInvoke in CL_Invocation.ps1 module
status: experimental
author: oscd.community, Natalia Shornikova
date: 2020/10/14
modified: 2021/05/21
references:
- https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSScripts/Cl_invocation.yml
- https://twitter.com/bohops/status/948061991012327424
@@ -22,5 +23,6 @@ detection:
condition: selection2 | count(ScriptBlockText) by Computer > 2
# PS > Import-Module c:\Windows\diagnostics\system\Audio\CL_Invocation.ps1
# PS > SyncInvoke c:\Evil.exe
falsepositives: Unknown
falsepositives:
- Unknown
level: high