Update rules/windows/image_load/image_load_alternate_powershell_hosts_moduleload.yml
This commit is contained in:
committed by
GitHub
parent
ae2c09f866
commit
f312455db5
@@ -28,7 +28,6 @@ detection:
|
||||
- 'C:\Program Files\Citrix\ConfigSync\'
|
||||
filter_aurora:
|
||||
# This filter is to avoid a race condition FP with this specific ETW provider in aurora
|
||||
Provider_Name: Microsoft-Windows-Kernel-Process
|
||||
Image: null
|
||||
condition: selection and not 1 of filter_*
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user