Skip to content

Commit

Permalink
rule: reduced level of rule to medium due to FPs
Browse files Browse the repository at this point in the history
  • Loading branch information
Florian Roth committed Nov 9, 2019
1 parent faeccf0 commit fbe138e
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion rules/windows/sysmon/sysmon_susp_file_characteristics.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ references:
- https://www.virustotal.com/#/file/276a765a10f98cda1a38d3a31e7483585ca3722ecad19d784441293acf1b7beb/detection
author: Markus Neis
date: 2018/11/22
modified: 2019/11/09
tags:
- attack.defense_evasion
- attack.execution
Expand All @@ -29,4 +30,4 @@ fields:
- ParentCommandLine
falsepositives:
- Unknown
level: high
level: medium

0 comments on commit fbe138e

Please sign in to comment.