fix: FPs
This commit is contained in:
@@ -7,7 +7,7 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1546/015/
|
||||
author: Maxime Thiebaut (@0xThiebaut), oscd.community, Cédric Hien
|
||||
date: 2020/04/14
|
||||
modified: 2022/04/04
|
||||
modified: 2022/07/07
|
||||
logsource:
|
||||
category: registry_set
|
||||
product: windows
|
||||
@@ -67,6 +67,8 @@ detection:
|
||||
Details|startswith:
|
||||
- 'C:\Program Files\'
|
||||
- 'C:\Program Files (x86)\'
|
||||
filter_programdata:
|
||||
Details|startswith: 'C:\ProgramData\Microsoft\'
|
||||
filter_gameservice:
|
||||
Details|contains: 'C:\WINDOWS\system32\GamingServicesProxy.dll'
|
||||
condition: selection and not 1 of filter*
|
||||
|
||||
Reference in New Issue
Block a user