Files
sigma-rules/rules/windows
Samirbous 0a6f9c6ddf [Rule Tuning] Suspicious Execution via Scheduled Task (#2235)
Excluding`?:\\ProgramData` and few other noisy FP pattern by process.args + name to reduce users alert fatigue.

(cherry picked from commit 0f7b29918c)
2022-08-15 19:51:18 +00:00
..