Commit b586c73
[Rule Tuning] 3rd Party EDR - Add Crowdstrike FDR support - 3 (#4222)
Removed changes from:
- rules/windows/defense_evasion_masquerading_trusted_directory.toml
- rules/windows/defense_evasion_wsl_child_process.toml
- rules/windows/execution_apt_solarwinds_backdoor_child_cmd_powershell.toml
- rules/windows/execution_enumeration_via_wmiprvse.toml
- rules/windows/execution_initial_access_foxmail_exploit.toml
- rules/windows/execution_suspicious_cmd_wmi.toml
- rules/windows/execution_suspicious_pdf_reader.toml
- rules/windows/execution_via_compiled_html_file.toml
- rules/windows/execution_via_mmc_console_file_unusual_path.toml
(selectively cherry picked from commit 2b6116e)1 parent 01f12f1 commit b586c73
1 file changed
+4
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
| 31 | + | |
31 | 32 | | |
32 | 33 | | |
33 | 34 | | |
| |||
0 commit comments