Skip to content

Commit 78a78c7

Browse files
authored
Merge PR #5229 from @dsplice - Update Potential APT FIN7 Exploitation Activity
update: Potential APT FIN7 Exploitation Activity - Add false positive description
1 parent eda06d1 commit 78a78c7

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules-emerging-threats/2024/TA/FIN7/proc_creation_win_apt_fin7_exploitation_indicators.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -25,5 +25,5 @@ detection:
2525
Image|endswith: '\notepad++.exe'
2626
condition: 1 of selection_*
2727
falsepositives:
28-
- Unknown
28+
- Notepad++ can legitimately spawn cmd (Open Containing Folder in CMD)
2929
level: medium

0 commit comments

Comments
 (0)