only FPs with no way to tune other than opening the rule for easy evasion by excluding by process.executable/args). Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>