Update 900000-exclusion_rules.xml

This commit is contained in:
taylor_socfortress
2023-06-20 08:29:55 -05:00
committed by GitHub
parent 6bb89a23db
commit 2ca470be98

View File

@@ -258,7 +258,7 @@
</rule>
<!-- Exclude MicroSoft Teams -->
<rule id="900040" level="1">
<if_sid>92910</if_sid>
<if_sid>92910,106117</if_sid>
<field name="win.eventdata.sourceImage" type="pcre2">(?i)C:\\\\ProgramData\\\\.*\\\\Microsoft\\\\Teams\\\\current\\\\Teams.exe$|</field>
<description>Exclude Microsoft Teams</description>
<options>no_full_log</options>