FP: ignore Amazon aws powershell

This commit is contained in:
Tim Shelton
2022-05-26 14:45:00 +00:00
parent c7b90f108f
commit b78386d372
@@ -112,11 +112,13 @@ detection:
- 'Invoke-SMBScanner'
- 'Invoke-Mimikittenz'
- 'Invoke-AllChecks'
false_positives:
false_positive1:
ScriptBlockText|contains:
- Get-SystemDriveInfo # http://bheltborg.dk/Windows/WinSxS/amd64_microsoft-windows-maintenancediagnostic_31bf3856ad364e35_10.0.10240.16384_none_91ef7543a4514b5e/CL_Utility.ps1
- C:\ProgramData\Amazon\EC2-Windows\Launch\Module\Scripts\Set-Wallpaper.ps1 # false positive form Amazon EC2
condition: select_Malicious and not false_positives
false_positive2:
ScriptBlockText|startswith: '# Copyright 2016 Amazon.com, Inc. or its affiliates. All Rights Reserved'
condition: select_Malicious and not false_positive*
falsepositives:
- Unknown
level: high