Fixed rule
This commit is contained in:
@@ -47,7 +47,7 @@ detection:
|
||||
- wbadmin.exe
|
||||
- icacls.exe
|
||||
- diskpart.exe
|
||||
timeframe: 5min
|
||||
timeframe: 5m
|
||||
condition: selection | count() by MachineName > 5
|
||||
falsepositives:
|
||||
- False positives depend on scripts and administrative tools used in the monitored environment
|
||||
|
||||
Reference in New Issue
Block a user