Update proc_creation_win_commandline_path_traversal_evasion.yml
Fix FP with Citrix launcher
This commit is contained in:
+3
-1
@@ -24,8 +24,10 @@ detection:
|
||||
selection2:
|
||||
CommandLine|contains: '.exe\..\'
|
||||
filter:
|
||||
CommandLine|contains: '\Google\Drive\googledrivesync.exe\..\'
|
||||
- CommandLine|contains: '\Google\Drive\googledrivesync.exe\..\'
|
||||
- CommandLine|contains: '\Citrix\Virtual Smart Card\Citrix.Authentication.VirtualSmartcard.Launcher.exe\..\'
|
||||
condition: 1 of selection* and not filter
|
||||
falsepositives:
|
||||
- Google Drive
|
||||
- Citrix
|
||||
level: high
|
||||
|
||||
Reference in New Issue
Block a user