Add default path to filter for explorer in exe anomaly rule

This commit is contained in:
Karneades
2019-04-21 17:40:52 +02:00
parent 38d548868d
commit b47900fbee
@@ -33,6 +33,7 @@ detection:
Image:
- 'C:\Windows\System32\\*'
- 'C:\Windows\SysWow64\\*'
- 'C:\Windows\explorer.exe'
condition: selection and not filter
falsepositives:
- Exotic software