Skip to content

Commit

Permalink
docs: improved false positive notes
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Oct 12, 2020
1 parent e7c6794 commit 0d0cda0
Showing 1 changed file with 1 addition and 2 deletions.
3 changes: 1 addition & 2 deletions rules/windows/process_creation/win_susp_wmi_execution.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,5 @@ tags:
- attack.t1047
- car.2016-03-002
falsepositives:
- Will need to be tuned
- If using Splunk, I recommend | stats count by Computer,CommandLine following for easy hunting by Computer/CommandLine.
- If using Splunk, we recommend | stats count by Computer,CommandLine following for easy hunting by Computer/CommandLine
level: medium

0 comments on commit 0d0cda0

Please sign in to comment.