Merge pull request #796 from EccoTheFlintstone/fp

add more false positives
This commit is contained in:
Florian Roth
2020-05-26 13:20:23 +02:00
committed by GitHub
@@ -32,6 +32,9 @@ detection:
- '\WmiAPsrv.exe'
- '\svchost.exe'
- '\DeviceCensus.exe'
- '\CompatTelRunner.exe'
- '\sdiagnhost.exe'
- '\SIHClient.exe'
condition: selection and not filter
fields:
- ComputerName