Merge pull request #796 from EccoTheFlintstone/fp
add more false positives
This commit is contained in:
@@ -32,6 +32,9 @@ detection:
|
||||
- '\WmiAPsrv.exe'
|
||||
- '\svchost.exe'
|
||||
- '\DeviceCensus.exe'
|
||||
- '\CompatTelRunner.exe'
|
||||
- '\sdiagnhost.exe'
|
||||
- '\SIHClient.exe'
|
||||
condition: selection and not filter
|
||||
fields:
|
||||
- ComputerName
|
||||
|
||||
Reference in New Issue
Block a user