fix: too many false positives with in-memory detection rule
This commit is contained in:
@@ -54,6 +54,6 @@ fields:
|
||||
- SourceImage
|
||||
- TargetImage
|
||||
- CallTrace
|
||||
level: high
|
||||
level: medium # too many false positives
|
||||
falsepositives:
|
||||
- SysInternals Process Explorer
|
||||
|
||||
Reference in New Issue
Block a user