Skip to content

Commit

Permalink
Update win_susp_multiple_files_renamed_or_deleted.yml
Browse files Browse the repository at this point in the history
  • Loading branch information
vburov authored Oct 29, 2020
1 parent 683824e commit ab60fdc
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@ detection:
timeframe: 30s
condition: selection | count() by SubjectLogonId > 10
falsepositives:
- software uninstallation
- files restore activities
- Software uninstallation
- Files restore activities
level: high

0 comments on commit ab60fdc

Please sign in to comment.