Skip to content

Commit

Permalink
fix: FPs with Wincred in log files
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Nov 20, 2021
1 parent dfbaadf commit c746283
Showing 1 changed file with 1 addition and 2 deletions.
3 changes: 1 addition & 2 deletions rules/windows/builtin/win_av_relevant_match.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ detection:
- "Webshell"
- "Portscan"
- "Mimikatz"
- "WinCred"
- ".WinCred." # . are needed to avoid false positives with many other strings
- "PlugX"
- "Korplug"
- "Pwdump"
Expand All @@ -33,7 +33,6 @@ detection:
filter:
- "Keygen"
- "Crack"
- "wincredui"
condition: keywords and not filter
falsepositives:
- Some software piracy tools (key generators, cracks) are classified as hack tools
Expand Down

0 comments on commit c746283

Please sign in to comment.