fix: FP with In-memory PowerShell rule and Visual Studio
This commit is contained in:
@@ -39,6 +39,7 @@ detection:
|
||||
- '\Microsoft SQL Server Management Studio *\Common*\IDE\Ssms.exe'
|
||||
- '\IDE\devenv.exe'
|
||||
- '\ServiceHub.VSDetouredHost.exe'
|
||||
- '\ServiceHub.SettingsHost.exe'
|
||||
# User: 'NT AUTHORITY\SYSTEM' # if set, matches all powershell processes not launched by SYSTEM
|
||||
condition: selection and not filter
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user