Update win_susp_multiple_files_renamed_or_deleted.yml

This commit is contained in:
Vasiliy Burov
2020-10-29 23:38:22 +03:00
committed by GitHub
parent 683824ee46
commit ab60fdcef4
@@ -22,6 +22,6 @@ detection:
timeframe: 30s
condition: selection | count() by SubjectLogonId > 10
falsepositives:
- software uninstallation
- files restore activities
- Software uninstallation
- Files restore activities
level: high